{"id":"UBUNTU-CVE-2013-7449","details":"The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.","modified":"2025-09-08T16:43:06Z","published":"2016-04-21T14:59:00Z","upstream":["CVE-2013-7449"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-7449"},{"type":"REPORT","url":"http://seclists.org/oss-sec/2016/q2/17"},{"type":"REPORT","url":"http://seclists.org/oss-sec/2015/q1/342"},{"type":"REPORT","url":"https://github.com/hexchat/hexchat/issues/524"},{"type":"REPORT","url":"https://launchpad.net/bugs/1565000"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1081839"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-7449"}],"affected":[{"package":{"name":"hexchat","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/hexchat@2.9.6.1-2ubuntu0.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.6.1-2ubuntu0.1"}]}],"versions":["2.9.6.1-1","2.9.6.1-1ubuntu1","2.9.6.1-2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"hexchat","binary_version":"2.9.6.1-2ubuntu0.1"},{"binary_name":"hexchat-common","binary_version":"2.9.6.1-2ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7449.json"}},{"package":{"name":"xchat-gnome","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/xchat-gnome@1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2"}]}],"versions":["1:0.30.0~git20110821.e2a400-0.2ubuntu9","1:0.30.0~git20110821.e2a400-0.2ubuntu10","1:0.30.0~git20110821.e2a400-0.2ubuntu11","1:0.30.0~git20110821.e2a400-0.2ubuntu12","1:0.30.0~git20131003.d20b8d-2ubuntu1","1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12","1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"xchat-gnome","binary_version":"1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2"},{"binary_version":"1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2","binary_name":"xchat-gnome-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-7449.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}