Description
libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9Confidentiality: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
2GHSAGHSA-42c4-xg6q-8r33: libgadu before 1↗2022-05-17 ▶ OSVCVE-2013-4488: libgadu before 1↗2014-10-10 ▶ 📋Vendor Advisories
2Red Hatlibgadu: missing ssl certificate validation↗2013-06-02 ▶ DebianCVE-2013-4488: libgadu - libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which...↗2013 ▶ 📄Research Papers
1arXivSpecification-Guided Vulnerability Detection with Large Language Models↗2025-11-06 ▶ 💬Community
2BugzillaCVE-2013-4488 libgadu: missing ssl certificate validation [fedora-all]↗2013-11-01 ▶ BugzillaCVE-2013-4488 libgadu: missing ssl certificate validation↗2013-11-01 ▶