Ubuntu Security Notice USN-2945-1
4th April, 2016
xchat-gnome vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary
XChat-GNOME could be made to expose sensitive information over the network.
Software description
- xchat-gnome - simple and featureful IRC client for GNOME
Details
It was discovered that XChat-GNOME incorrectly verified the hostname in an
SSL certificate. An attacker could trick XChat-GNOME into trusting a rogue
server's certificate, which was signed by a trusted certificate authority,
to perform a man-in-the-middle attack.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 15.10:
- xchat-gnome 1:0.30.0~git20141005.816798-0ubuntu6.2
- Ubuntu 14.04 LTS:
- xchat-gnome 1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2
- Ubuntu 12.04 LTS:
- xchat-gnome 1:0.30.0~git20110821.e2a400-0.2ubuntu4.3
To update your system, please follow these instructions: http://ift.tt/17VXqjU.
After a standard system update you need to restart XChat-GNOME to make
all the necessary changes.
References
from Ubuntu Security Notices http://ift.tt/1TwJTHk
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.