USN-2945-1: XChat-GNOME vulnerability

Publication date

4 April 2016

Overview

XChat-GNOME could be made to expose sensitive information over the network.


Packages

  • xchat-gnome - simple and featureful IRC client for GNOME

Details

It was discovered that XChat-GNOME incorrectly verified the hostname in an
SSL certificate. An attacker could trick XChat-GNOME into trusting a rogue
server's certificate, which was signed by a trusted certificate authority,
to perform a machine-in-the-middle attack.

It was discovered that XChat-GNOME incorrectly verified the hostname in an
SSL certificate. An attacker could trick XChat-GNOME into trusting a rogue
server's certificate, which was signed by a trusted certificate authority,
to perform a machine-in-the-middle attack.

Update instructions

After a standard system update you need to restart XChat-GNOME to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:


Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›