Advisories ยป MGASA-2015-0050

Updated hexchat packages fix security vulnerability

Publication date: 05 Feb 2015
Modification date: 05 Feb 2015
Type: security
Affected Mageia releases : 4

Description

HexChat did not verify that the server hostname matched the domain name in 
the subject's Common Name (CN) or subjectAltName field in X.509 
certificates. This could allow a man-in-the-middle attacker to spoof an 
SSL server if they had a certificate that was valid for any domain name.
                

References

SRPMS

4/core