CVE-2009-3026

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pidgin:pidgin:2.6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891 -
References () http://developer.pidgin.im/ticket/8131 - () http://developer.pidgin.im/ticket/8131 -
References () http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279 - Patch () http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279 - Patch
References () http://secunia.com/advisories/37071 - () http://secunia.com/advisories/37071 -
References () http://www.openwall.com/lists/oss-security/2009/08/24/2 - () http://www.openwall.com/lists/oss-security/2009/08/24/2 -
References () http://www.securityfocus.com/bid/36368 - () http://www.securityfocus.com/bid/36368 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/53000 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/53000 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757 -

Information

Published : 2009-08-31 20:30

Updated : 2024-11-21 01:06


NVD link : CVE-2009-3026

Mitre link : CVE-2009-3026

CVE.ORG link : CVE-2009-3026


JSON object : View

Products Affected

pidgin

  • pidgin
CWE
CWE-310

Cryptographic Issues