Overview: 1 vulnerability
WSA |
CVE |
Score |
Severity |
Issue |
Vulnerability type |
Scope |
Versions |
Fix |
Release date |
WSA-2011-1 |
CVE-2011-1428 |
5.3 |
|
Possible man-in-the-middle attack in TLS connection to IRC server. |
Improper certificate validation |
IRC |
0.1.3 → 0.3.4 |
0.3.5 |
|
WSA-2011-1: [IRC] Possible man-in-the-middle attack in TLS connection to IRC server.
Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
(
detail)
Improper certificate validation
(
detail)
Affected versions
0.1.3 → 0.3.4
Description
Due to insufficient check of TLS certificate in IRC plugin, man-in-the-middle attackers can spoof a server via an arbitrary certificate.
Mitigation
There is no known mitigation.
The upgrade to the latest stable version is highly recommended.