Bugzilla – Bug 974416
VUL-0: CVE-2013-7449: xchat: Doesn't properly verify SSL certificates
Last modified: 2018-02-15 15:37:16 UTC
CVE-2013-7449 xchat doesn't check if the certificat is actually for the server it connects to. Fix in: https://github.com/hexchat/hexchat/commit/c9b63f7f9be01692b03fa15275135a4910a7e02d References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7449 http://www.openwall.com/lists/oss-security/2015/01/30/18 http://www.openwall.com/lists/oss-security/2015/01/29/24 http://www.openwall.com/lists/oss-security/2015/01/29/27 http://seclists.org/oss-sec/2016/q2/17 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7449.html https://github.com/hexchat/hexchat/commit/c9b63f7f9be01692b03fa15275135a4910a7e02d
bugbot adjusting priority
The fix is available in hexchat 2.12.0 which is the version we ship in SLE12 SP2 and SP3. Assign back to security team.
hexchat is fixed, xchat not supported anymore