Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4663-xvr2-gqpr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 15 лет назад

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

nvd
почти 15 лет назад

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

debian
почти 15 лет назад

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does ...

EPSS

Процентиль: 38%
0.00165
Низкий

Дефекты

CWE-20