6.8
CVSSv2

CVE-2010-1155

Published: 16/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Irssi prior to 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof IRC servers via an arbitrary certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

irssi irssi 0.8.5

irssi irssi

irssi irssi 0.8.14

irssi irssi 0.8.10

irssi irssi 0.8.8

irssi irssi 0.8.7

irssi irssi 0.8.12

irssi irssi 0.8.11

irssi irssi 0.8.3

irssi irssi 0.8.2

irssi irssi 0.8.13

irssi irssi 0.8.6

irssi irssi 0.8.1

irssi irssi 0.8.0

irssi irssi 0.8.4

irssi irssi 0.8.9

Vendor Advisories

USN-929-1 fixed vulnerabilities in irssi The upstream changes introduced a regression when using irssi with SSL and an IRC proxy This update fixes the problem ...
It was discovered that irssi did not perform certificate host validation when using SSL connections An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications (CVE-2010-1155) ...