Bug#829730: xchat-gnome: CVE-2013-7449

2016-07-05 Thread Josselin Mouette
Hi, Le mardi 05 juillet 2016 à 22:15 +0200, Michael Biebl a écrit : > We have a supported successor/alternative with hexchat, so I'm inclined > to request the removal of the package. > Joss et al, do you see any reason why we should keep the package? I don’t think we should. Maybe replace it

Bug#829730: xchat-gnome: CVE-2013-7449

2016-07-05 Thread Michael Biebl
Am 05.07.2016 um 17:53 schrieb Salvatore Bonaccorso: > Source: xchat-gnome > CVE-2013-7449[0]: > | The ssl_do_connect function in common/server.c in HexChat before > | 2.10.2, XChat, and XChat-GNOME does not verify that the server > | hostname matches a domain name in the X.509 certificate, which

Bug#829730: xchat-gnome: CVE-2013-7449

2016-07-05 Thread Salvatore Bonaccorso
Source: xchat-gnome Version: 1:0.30.0~git20110821.e2a400-0.2 Severity: important Tags: security upstream Hi, the following vulnerability was published for xchat-gnome. CVE-2013-7449[0]: | The ssl_do_connect function in common/server.c in HexChat before | 2.10.2, XChat, and XChat-GNOME does not