Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gu1

#44716of 53,622
5.8Total CVSS
Vulnerabilities · 1
PT-2011-3123
5.8
2011-03-16
Weechat · Weechat · CVE-2011-1428
**Name of the Vulnerable Software and Affected Versions** Wee Enhanced Environment for Chat (aka WeeChat) versions 0.3.4 and earlier **Description** The issue arises from improper verification that the server hostname matches the domain name of the subject of an X.509 certificate. This allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, due to incorrect use of the GnuTLS API. **Recommendations** For Wee Enhanced Environment for Chat (aka WeeChat) versions 0.3.4 and earlier, update to a version that properly verifies the server hostname against the domain name of the X.509 certificate subject.