Vulnerability Name: | CVE-2010-1155 (CCN-57790) | ||||||||||||||||||||||||
Assigned: | 2010-04-11 | ||||||||||||||||||||||||
Published: | 2010-04-11 | ||||||||||||||||||||||||
Updated: | 2017-08-17 | ||||||||||||||||||||||||
Summary: | Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-1155 Source: CONFIRM Type: UNKNOWN http://github.com/ensc/irssi-proxy/commit/85bbc05b21678e80423815d2ef1dfe26208491ab Source: CONFIRM Type: UNKNOWN http://irssi.org/news Source: CONFIRM Type: UNKNOWN http://irssi.org/news/ChangeLog Source: FEDORA Type: UNKNOWN FEDORA-2010-6629 Source: SUSE Type: UNKNOWN SUSE-SR:2010:011 Source: MLIST Type: UNKNOWN [oss-security] 20100411 CVE request: irssi 0.8.15 Source: MLIST Type: UNKNOWN [oss-security] 20100412 Re: CVE request: irssi 0.8.15 Source: MLIST Type: UNKNOWN [oss-security] 20100413 Re: CVE request: irssi 0.8.15 Source: MLIST Type: UNKNOWN [oss-security] 20100413 Re: CVE request: irssi 0.8.15 Source: CCN Type: SA39365 irssi Denial of Service and SSL Hostname Verification Vulnerabilities Source: SECUNIA Type: Vendor Advisory 39365 Source: SECUNIA Type: UNKNOWN 39620 Source: SECUNIA Type: UNKNOWN 39797 Source: SLACKWARE Type: UNKNOWN SSA:2010-116-01 Source: CCN Type: Irssi Web site Irssi 0.8.15 Released Source: CCN Type: OSVDB ID: 63888 irssi X.509 Certificate Common Name (CN) Field Handling SSL MiTM Weakness Source: CCN Type: BID-39377 Irssi Denial of Service and SSL Hostname Verification Security Bypass Vulnerabilities Source: CCN Type: USN-929-1 irssi vulnerabilities Source: UBUNTU Type: UNKNOWN USN-929-1 Source: CCN Type: USN-929-2 irssi regression Source: VUPEN Type: Patch, Vendor Advisory ADV-2010-0856 Source: VUPEN Type: UNKNOWN ADV-2010-0987 Source: VUPEN Type: UNKNOWN ADV-2010-1107 Source: VUPEN Type: UNKNOWN ADV-2010-1110 Source: XF Type: UNKNOWN irssi-hostname-mitm(57790) Source: XF Type: UNKNOWN irssi-hostname-mitm(57790) Source: SUSE Type: SUSE-SR:2010:011 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |