CVE-2011-1428: Input Validation
Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability description for CVE-2011-1428?
CVE-2011-1428 describes a flaw in WeeChat 0.3.4 and earlier where the software does not verify that the server hostname matches the domain name of the X.509 certificate, allowing man-in-the-middle attacks.
What is the severity of CVE-2011-1428?
CVE-2011-1428 has been classified as a moderate severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2011-1428?
To fix CVE-2011-1428, it is recommended to upgrade to a version of WeeChat later than 0.3.4 where this issue has been addressed.
What versions of WeeChat are affected by CVE-2011-1428?
CVE-2011-1428 affects WeeChat versions 0.3.4 and earlier.
Can CVE-2011-1428 lead to data interception?
Yes, CVE-2011-1428 can enable attackers to intercept and spoof communications, leading to potential data breaches.