Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3026

Опубликовано: 31 авг. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1:2.6.5-1ubuntu1
hardy

released

1:2.4.1-1ubuntu2.8
intrepid

released

1:2.5.2-0ubuntu1.6
jaunty

released

1:2.5.5-1ubuntu8.5
karmic

not-affected

1:2.6.2-1ubuntu7
upstream

needs-triage

Показывать по

EPSS

Процентиль: 66%
0.00526
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

nvd
больше 16 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

debian
больше 16 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly oth ...

github
больше 3 лет назад

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

fstec
около 16 лет назад

Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 66%
0.00526
Низкий

5 Medium

CVSS2