Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier...
Vulnerability Description
Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1428
Credits & Attribution
No credits recorded in the NVD database.
References
- http://savannah.nongnu.org/patch/index.php?7459
- http://www.securityfocus.com/bid/46612
- http://git.savannah.gnu.org/gitweb/?p=weechat.git%3Ba=commit%3Bh=c265cad1c95b84abfd4e8d861f25926ef13b5d91
- http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0671.html
- http://secunia.com/advisories/43543
More from flashtux
View All →Affected Vendor
flashtux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.