Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-1155

Опубликовано: 16 апр. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.

РелизСтатусПримечание
dapper

ignored

end of life
devel

released

0.8.14-1ubuntu3
hardy

released

0.8.12-3ubuntu3.2
intrepid

released

0.8.12-4ubuntu2.2
jaunty

released

0.8.12-6ubuntu1.2
karmic

released

0.8.14-1ubuntu1.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 73%
0.00788
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.

debian
больше 15 лет назад

Irssi before 0.8.15, when SSL is used, does not verify that the server ...

github
больше 3 лет назад

Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.

EPSS

Процентиль: 73%
0.00788
Низкий

6.8 Medium

CVSS2