XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
BID:72368
Info
XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
| Bugtraq ID: | 72368 |
| Class: | Design Error |
| CVE: |
CVE-2013-7449 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2015 12:00AM |
| Updated: | Jul 06 2016 02:21PM |
| Credit: | Nicholas Bebout |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
XChat is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
XChat is prone to a security-bypass vulnerability.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid in further attacks.
Exploit / POC
XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
XChat 'Comman Name' Field SSL Certificate Security Bypass Vulnerability
References:
References: