6.5
CVSSv3

CVE-2013-7449

Published: 21/04/2016 Updated: 20/07/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The ssl_do_connect function in common/server.c in HexChat prior to 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

xchat xchat -

xchat xchat gnome -

hexchat project hexchat

Vendor Advisories

Debian Bug report logs - #776609 xchat: CVE-2013-7449: XChat does not verify certificate host name Package: xchat; Maintainer for xchat is Gianfranco Costamagna <locutusofborg@debianorg>; Source for xchat is src:xchat (PTS, buildd, popcon) Reported by: Marian Sigler <m@qjymde> Date: Thu, 29 Jan 2015 22:33:02 UTC S ...