MEDIUM
pidgin: ignores SSL/TLS requirements with old jabber servers
Published Aug 31, 2009
5.0
MEDIUMCVSS 2.0
EPSS 1.30%
Description
protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
pidgin-0:2.6.2-2.el4
Fixed · RHSA-2009:1453
Red Hat Enterprise Linux 5
pidgin-0:2.6.2-2.el5
Fixed · RHSA-2009:1453
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | pidgin-0:2.6.2-2.el4 | Fixed | RHSA-2009:1453 |
| Red Hat Enterprise Linux 5 | pidgin-0:2.6.2-2.el5 | Fixed | RHSA-2009:1453 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891 x_refsource_CONFIRM
- http://developer.pidgin.im/ticket/8131 x_refsource_CONFIRM
- http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279 x_refsource_CONFIRMPatch
- http://secunia.com/advisories/37071 third-party-advisoryx_refsource_SECUNIA
- http://www.openwall.com/lists/oss-security/2009/08/24/2 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/36368 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-3026 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=519224 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53000 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3026
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3026
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 31, 2009
Updated Aug 7, 2024
Reserved Aug 31, 2009
Link CVE-2009-3026
CISA Vulnrichment
Updated n/a