VYPR
Unrated severityNVD Advisory· Published May 21, 2013· Updated Apr 29, 2026

CVE-2007-6746

CVE-2007-6746

Description

telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

Affected products

9
  • cpe:2.3:a:canonical:telepathy-idle:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:canonical:telepathy-idle:*:*:*:*:*:*:*:*range: <=0.1.14.1
    • cpe:2.3:a:canonical:telepathy-idle:0.1.10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:canonical:telepathy-idle:0.1.11.1:*:*:*:*:*:*:*
    • cpe:2.3:a:canonical:telepathy-idle:0.1.11.2:*:*:*:*:*:*:*
    • cpe:2.3:a:canonical:telepathy-idle:0.1.12.1:*:*:*:*:*:*:*
    • cpe:2.3:a:canonical:telepathy-idle:0.1.14:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.