Oval Definition:oval:org.mitre.oval:def:5757
Revision Date:2013-09-09Version:3
Title:Pidgin 2.6.0 and prior does not follow the require TLS/SSL preference
Description:protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-3026
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Pidgin
Definition Synopsis
  • Pidgin is installed
  • AND Pidgin version is less than or equal to 2.6.0
  • BACK