UBUNTU-CVE-2013-7449

Source
https://ubuntu.com/security/CVE-2013-7449
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7449.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-7449
Related
Published
2016-04-21T14:59:00Z
Modified
2025-01-13T10:21:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The ssldoconnect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

References

Affected packages

Ubuntu:14.04:LTS / hexchat

Package

Name
hexchat
Purl
pkg:deb/ubuntu/hexchat@2.9.6.1-2ubuntu0.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.6.1-2ubuntu0.1

Affected versions

2.*

2.9.6.1-1
2.9.6.1-1ubuntu1
2.9.6.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.9.6.1-2ubuntu0.1",
            "binary_name": "hexchat"
        },
        {
            "binary_version": "2.9.6.1-2ubuntu0.1",
            "binary_name": "hexchat-common"
        },
        {
            "binary_version": "2.9.6.1-2ubuntu0.1",
            "binary_name": "hexchat-dbgsym"
        }
    ]
}

Ubuntu:14.04:LTS / xchat-gnome

Package

Name
xchat-gnome
Purl
pkg:deb/ubuntu/xchat-gnome@1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2

Affected versions

1:0.*

1:0.30.0~git20110821.e2a400-0.2ubuntu9
1:0.30.0~git20110821.e2a400-0.2ubuntu10
1:0.30.0~git20110821.e2a400-0.2ubuntu11
1:0.30.0~git20110821.e2a400-0.2ubuntu12
1:0.30.0~git20131003.d20b8d-2ubuntu1
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12
1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2",
            "binary_name": "xchat-gnome"
        },
        {
            "binary_version": "1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2",
            "binary_name": "xchat-gnome-common"
        },
        {
            "binary_version": "1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2",
            "binary_name": "xchat-gnome-dbgsym"
        }
    ]
}

Ubuntu:16.04:LTS / hexchat

Package

Name
hexchat
Purl
pkg:deb/ubuntu/hexchat@2.10.2-1ubuntu2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.2-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-common"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-dbgsym"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-perl"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-perl-dbgsym"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-plugins"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-plugins-dbgsym"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-python"
        },
        {
            "binary_version": "2.10.2-1ubuntu2",
            "binary_name": "hexchat-python-dbgsym"
        }
    ]
}

Ubuntu:16.04:LTS / xchat-gnome

Package

Name
xchat-gnome
Purl
pkg:deb/ubuntu/xchat-gnome@1:0.30.0~git20141005.816798-0ubuntu9?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:0.30.0~git20141005.816798-0ubuntu9

Affected versions

1:0.*

1:0.30.0~git20141005.816798-0ubuntu6
1:0.30.0~git20141005.816798-0ubuntu7
1:0.30.0~git20141005.816798-0ubuntu8

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1:0.30.0~git20141005.816798-0ubuntu9",
            "binary_name": "xchat-gnome"
        },
        {
            "binary_version": "1:0.30.0~git20141005.816798-0ubuntu9",
            "binary_name": "xchat-gnome-common"
        },
        {
            "binary_version": "1:0.30.0~git20141005.816798-0ubuntu9",
            "binary_name": "xchat-gnome-dbgsym"
        }
    ]
}