Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3694

Опубликовано: 29 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

РелизСтатусПримечание
devel

released

1:2.10.9-0ubuntu8
esm-infra-legacy/trusty

released

1:2.10.9-0ubuntu3.2
lucid

ignored

end of life
precise

released

1:2.10.3-0ubuntu1.6
trusty

released

1:2.10.9-0ubuntu3.2
trusty/esm

released

1:2.10.9-0ubuntu3.2
upstream

released

2.10.10-1
utopic

released

1:2.10.9-0ubuntu7.1

Показывать по

EPSS

Процентиль: 79%
0.0127
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 3.1
redhat
около 11 лет назад

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

nvd
около 11 лет назад

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

debian
около 11 лет назад

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/ ...

github
больше 3 лет назад

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

oracle-oval
больше 8 лет назад

ELSA-2017-1854: pidgin security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 79%
0.0127
Низкий

6.4 Medium

CVSS2