LOW
pidgin: SSL/TLS plug-ins failed to check Basic Constraints
Published Oct 29, 2014
3.1
LOWCVSS 3.0
EPSS 2.35%
Description
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 12.04
- 14.04
- 14.10
Configuration 3
- 7.0
Configuration 4
OR
- ≤ 2.10.9
- 2.10.0
- 2.10.1
- 2.10.2
- 2.10.3
- 2.10.4
- 2.10.5
- 2.10.6
- 2.10.7
- 2.10.8
No data.
Red Hat Enterprise Linux 7
pidgin-0:2.10.11-5.el7
Fixed · RHSA-2017:1854
Red Hat Enterprise Linux 5
pidgin
Will not fix
Red Hat Enterprise Linux 6
pidgin
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | pidgin-0:2.10.11-5.el7 | Fixed | RHSA-2017:1854 |
| Red Hat Enterprise Linux 5 | pidgin | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | pidgin | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://hg.pidgin.im/pidgin/main/rev/2e4475087f04 x_refsource_CONFIRMIssue Tracking
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00023.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00037.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://pidgin.im/news/security/?id=86 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/60741 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61968 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-3055 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.ubuntu.com/usn/USN-2390-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1854 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2014-3694 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1154908 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2014-3694
- https://www.cve.org/CVERecord?id=CVE-2014-3694
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 29, 2014
Updated Aug 6, 2024
Reserved May 14, 2014
Link CVE-2014-3694
CISA Vulnrichment
Updated n/a