5.8
CVSSv2

CVE-2011-1428

Published: 16/03/2011 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and previous versions does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle malicious users to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flashtux weechat 0.2.3

flashtux weechat 0.2.6.3

flashtux weechat 0.0.4

flashtux weechat 0.2.6.1

flashtux weechat 0.1.8

flashtux weechat 0.3.1

flashtux weechat 0.1.0

flashtux weechat 0.0.2

flashtux weechat 0.3.2

flashtux weechat 0.1.7

flashtux weechat 0.1.1

flashtux weechat 0.1.3

flashtux weechat 0.0.7

flashtux weechat 0.0.5

flashtux weechat 0.1.9

flashtux weechat 0.2.6

flashtux weechat 0.3.0

flashtux weechat 0.1.5

flashtux weechat 0.1.6

flashtux weechat 0.2.6.2

flashtux weechat 0.1.4

flashtux weechat 0.0.8

flashtux weechat 0.2.1

flashtux weechat 0.0.1

flashtux weechat 0.3.1.1

flashtux weechat 0.2.0

flashtux weechat 0.0.9

flashtux weechat 0.0.6

flashtux weechat 0.2.2

flashtux weechat 0.1.2

flashtux weechat 0.0.3

flashtux weechat 0.3.3

flashtux weechat

flashtux weechat 0.2.5

flashtux weechat 0.2.4

Vendor Advisories

Two security issues have been discovered in WeeChat, a fast, light and extensible chat client: CVE-2011-1428 X509 certificates were incorrectly validated CVE-2012-5534 The hook_process function in the plugin API allowed the execution of arbitrary shell commands For the stable distribution (squeeze), these problems have been fixed in v ...