Back to search
CVE-2011-1428
Published: Mar 16, 2011
Modified: Sep 17, 2024
PUBLISHED
Description
Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://savannah.nongnu.org/patch/index.php?7459
x_refsource_CONFIRM
46612
vdb-entry
x_refsource_BID
20110227 weechat does not properly use gnutls and allow an attacker to bypass certificate verification
mailing-list
x_refsource_FULLDISC
43543
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now