USN-2945-1: XChat-GNOME vulnerability
4 April 2016
XChat-GNOME could be made to expose sensitive information over the network.
Releases
Packages
- xchat-gnome - simple and featureful IRC client for GNOME
Details
It was discovered that XChat-GNOME incorrectly verified the hostname in an
SSL certificate. An attacker could trick XChat-GNOME into trusting a rogue
server's certificate, which was signed by a trusted certificate authority,
to perform a machine-in-the-middle attack.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10
Ubuntu 14.04
Ubuntu 12.04
After a standard system update you need to restart XChat-GNOME to make
all the necessary changes.