Open Vulnerability and Assessment Language (OVAL)
Offical Language Release Repository Downloads News — November 5, 2009 Search
link to OVAL home page

View Definition

Definition Id: oval:org.mitre.oval:def:5757 Date: 2009-09-24
Title: Pidgin 2.6.0 and prior does not follow the require TLS/SSL preference
Description: protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
Version: 1 Class: vulnerability
Status: ACCEPTED Reference(s): CVE-2009-3026
Family: windows
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Product(s): Pidgin Messanger
Definition Synopsis: