CVE-2009-3026

Impact:
Low
Public Date:
2009-01-15
Bugzilla:
519224: CVE-2009-3026 pidgin: ignores SSL/TLS requirements with old jabber servers

The MITRE CVE dictionary describes this issue as:

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

Find out more about CVE-2009-3026 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat has released updates to correct this issue:
https://rhn.redhat.com/errata/RHSA-2009-1453.html

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (pidgin) RHSA-2009:1453 2009-09-21
Red Hat Enterprise Linux Optional Productivity Applications (v. 5 server) (pidgin) RHSA-2009:1453 2009-09-21
Red Hat Enterprise Linux 5 (pidgin) RHSA-2009:1453 2009-09-21

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.