CVE Vulnerabilities

CVE-2009-3026

Published: Aug 31, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the require TLS/SSL preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

Affected Software

NameVendorStart VersionEnd Version
PidginPidgin2.6.0 (including)2.6.0 (including)
Red Hat Enterprise Linux 4RedHatpidgin-0:2.6.2-2.el4*
Red Hat Enterprise Linux 5RedHatpidgin-0:2.6.2-2.el5*
PidginUbuntuhardy*
PidginUbuntuintrepid*
PidginUbuntujaunty*

References