← Back

CVE-2013-7449

nvd nist
Published: Apr 21, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected (6)

1 product
Ubuntu Linux
2 products
Xchat
Xchat Gnome
Hexchat
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 15.10
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.10.1

Related CWEs

References (10)

Timeline

No history available yet.