UBUNTU-CVE-2013-7449

Source
https://ubuntu.com/security/CVE-2013-7449
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7449.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-7449
Upstream
Published
2016-04-21T14:59:00Z
Modified
2025-09-08T16:43:06Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The ssldoconnect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

References

Affected packages

Ubuntu:14.04:LTS / hexchat

Package

Name
hexchat
Purl
pkg:deb/ubuntu/hexchat@2.9.6.1-2ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.6.1-2ubuntu0.1

Affected versions

2.*

2.9.6.1-1
2.9.6.1-1ubuntu1
2.9.6.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "hexchat",
            "binary_version": "2.9.6.1-2ubuntu0.1"
        },
        {
            "binary_name": "hexchat-common",
            "binary_version": "2.9.6.1-2ubuntu0.1"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:14.04:LTS / xchat-gnome

Package

Name
xchat-gnome
Purl
pkg:deb/ubuntu/xchat-gnome@1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2

Affected versions

1:0.*

1:0.30.0~git20110821.e2a400-0.2ubuntu9
1:0.30.0~git20110821.e2a400-0.2ubuntu10
1:0.30.0~git20110821.e2a400-0.2ubuntu11
1:0.30.0~git20110821.e2a400-0.2ubuntu12
1:0.30.0~git20131003.d20b8d-2ubuntu1
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "xchat-gnome",
            "binary_version": "1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2"
        },
        {
            "binary_name": "xchat-gnome-common",
            "binary_version": "1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2"
        }
    ],
    "availability": "No subscription required"
}