CVE-2010-1155
published 2010-04-16CVE-2010-1155: Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.56%
72.5th percentile
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | irssi | < irssi 0.8.15-1 (bookworm) | irssi 0.8.15-1 (bookworm) |
| irssi | irssi | <= 0.8.15 | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | — | — |
| irssi | irssi | >= 0 < 0.8.15-1 | 0.8.15-1 |
| irssi | irssi | >= 0 < 0.8.15-1 | 0.8.15-1 |
| irssi | irssi | >= 0 < 0.8.15-1 | 0.8.15-1 |
| irssi | irssi | >= 0 < 0.8.15-1 | 0.8.15-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
irssi regression
vendor_ubuntu·2010-04-20·CVSS 6.8
[MEDIUM] irssi regression
Title: irssi regression
Summary: irssi regression
USN-929-1 fixed vulnerabilities in irssi. The upstream changes introduced a
regression when using irssi with SSL and an IRC proxy. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that irssi did not perform certificate host validation
when using SSL connections. An attacker could exploit this to perform a man
in the middle attack to view sensitive information or alter encrypted
communications. (CVE-2010-1155)
Aurelien Delaitre discovered that irssi could be made to dereference a NULL
pointer when a user left the channel. A remote attacker could cause a
denial of service via application crash. (CVE-2010-1156)
This update also adds SSLv3 and TLSv1 support, while disabling t
Ubuntu
irssi vulnerabilities
vendor_ubuntu·2010-04-15·CVSS 6.8
CVE-2010-1155 [MEDIUM] irssi vulnerabilities
Title: irssi vulnerabilities
Summary: irssi vulnerabilities
It was discovered that irssi did not perform certificate host validation
when using SSL connections. An attacker could exploit this to perform a man
in the middle attack to view sensitive information or alter encrypted
communications. (CVE-2010-1155)
Aurelien Delaitre discovered that irssi could be made to dereference a NULL
pointer when a user left the channel. A remote attacker could cause a
denial of service via application crash. (CVE-2010-1156)
This update also adds SSLv3 and TLSv1 support, while disabling the old,
insecure SSLv2 protocol.
Instructions: After a standard system upgrade you need to restart irssi to effect the
necessary changes.
Debian
CVE-2010-1155: irssi - Irssi before 0.8.15, when SSL is used, does not verify that the server hostname ...
vendor_debian·2010·CVSS 6.8
CVE-2010-1155 [MEDIUM] CVE-2010-1155: irssi - Irssi before 0.8.15, when SSL is used, does not verify that the server hostname ...
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.
Scope: local
bookworm: resolved (fixed in 0.8.15-1)
bullseye: resolved (fixed in 0.8.15-1)
forky: resolved (fixed in 0.8.15-1)
sid: resolved (fixed in 0.8.15-1)
trixie: resolved (fixed in 0.8.15-1)
GHSA
GHSA-hvgv-8rp6-894g: Irssi before 0
ghsa_unreviewed·2022-05-02
CVE-2010-1155 [MEDIUM] CWE-20 GHSA-hvgv-8rp6-894g: Irssi before 0
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.
OSV
CVE-2010-1155: Irssi before 0
osv·2010-04-16·CVSS 6.8
CVE-2010-1155 [MEDIUM] CVE-2010-1155: Irssi before 0
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.
No detection rules found.
No public exploits indexed.
http://github.com/ensc/irssi-proxy/commit/85bbc05b21678e80423815d2ef1dfe26208491abhttp://irssi.org/newshttp://irssi.org/news/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://marc.info/?l=oss-security&m=127098845125270&w=2http://marc.info/?l=oss-security&m=127110132019166&w=2http://marc.info/?l=oss-security&m=127116251220784&w=2http://marc.info/?l=oss-security&m=127119240204394&w=2http://secunia.com/advisories/39365http://secunia.com/advisories/39620http://secunia.com/advisories/39797http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.497301http://www.ubuntu.com/usn/USN-929-1http://www.vupen.com/english/advisories/2010/0856http://www.vupen.com/english/advisories/2010/0987http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/1110https://exchange.xforce.ibmcloud.com/vulnerabilities/57790http://github.com/ensc/irssi-proxy/commit/85bbc05b21678e80423815d2ef1dfe26208491abhttp://irssi.org/newshttp://irssi.org/news/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlhttp://marc.info/?l=oss-security&m=127098845125270&w=2http://marc.info/?l=oss-security&m=127110132019166&w=2http://marc.info/?l=oss-security&m=127116251220784&w=2http://marc.info/?l=oss-security&m=127119240204394&w=2http://secunia.com/advisories/39365http://secunia.com/advisories/39620http://secunia.com/advisories/39797http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.497301http://www.ubuntu.com/usn/USN-929-1http://www.vupen.com/english/advisories/2010/0856http://www.vupen.com/english/advisories/2010/0987http://www.vupen.com/english/advisories/2010/1107http://www.vupen.com/english/advisories/2010/1110https://exchange.xforce.ibmcloud.com/vulnerabilities/57790
2010-04-16
Published