CVE-2009-3026
Publication date 31 August 2009
Last updated 24 July 2024
Ubuntu priority
protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Status
Package | Ubuntu Release | Status |
---|---|---|
pidgin | ||
Notes
Patch details
Package | Patch details |
---|---|
pidgin |
References
Related Ubuntu Security Notices (USN)
- USN-886-1
- Pidgin vulnerabilities
- 18 January 2010