CVE-2009-3026

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:pidgin:pidgin:2.6.0:*:*:*:*:*:*:*

Information

Published : 2009-08-31 13:30

Updated : 2017-09-18 18:29


NVD link : CVE-2009-3026

Mitre link : CVE-2009-3026


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

pidgin

  • pidgin