Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3026

Опубликовано: 15 янв. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=519224pidgin: ignores SSL/TLS requirements with old jabber servers

EPSS

Процентиль: 66%
0.00526
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

nvd
больше 16 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

debian
больше 16 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly oth ...

github
больше 3 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

fstec
больше 16 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 66%
0.00526
Низкий

4.3 Medium

CVSS2