[CVE-2013-7449] xchat and derivatives don't validate ssl hostnames
Bug #1565000 reported by
Marc Deslauriers
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
hexchat (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | |||
Trusty |
Fix Released
|
Undecided
|
Unassigned | |||
Wily |
Fix Released
|
Undecided
|
Unassigned | |||
Xenial |
Fix Released
|
Undecided
|
Unassigned | |||
xchat (Ubuntu) | ||||||
Precise |
Won't Fix
|
Undecided
|
Unassigned | |||
Trusty |
Confirmed
|
Undecided
|
Unassigned | |||
Wily |
Confirmed
|
Undecided
|
Unassigned | |||
xchat-gnome (Ubuntu) |
Fix Released
|
Undecided
|
Marc Deslauriers | |||
Precise |
Fix Released
|
Undecided
|
Marc Deslauriers | |||
Trusty |
Fix Released
|
Undecided
|
Marc Deslauriers | |||
Wily |
Fix Released
|
Undecided
|
Marc Deslauriers | |||
Xenial |
Fix Released
|
Undecided
|
Marc Deslauriers |
Bug Description
http://
XChat did not verify that the server hostname matched the domain name in
the subject's Common Name (CN) or subjectAltName field in X.509
certificates. This could allow a man-in-the-middle attacker to spoof an
SSL server if they had a certificate that was valid for any domain name.
Also applied to hexchat and xchat-gnome.
no longer affects: | hexchat (Ubuntu Precise) |
no longer affects: | xchat (Ubuntu Xenial) |
no longer affects: | xchat (Ubuntu) |
summary: |
- xchat-gnome doesn't validate ssl hostnames + xchat and derivatives don't validate ssl hostnames |
summary: |
- xchat and derivatives don't validate ssl hostnames + [CVE-2013-7449] xchat and derivatives don't validate ssl hostnames |
To post a comment you must log in.
https:/ /github. com/hexchat/ hexchat/ issues/ 524 /github. com/hexchat/ hexchat/ commit/ c9b63f7f9be0169 2b03fa15275135a 4910a7e02d /bugzilla. redhat. com/show_ bug.cgi? id=1081839
https:/
https:/