[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2115 --- pidgin

ID: oval:org.secpod.oval:def:1701469Date: (C)2023-08-08   (M)2023-12-03
Class: PATCHFamily: unix




An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968

Platform:
Amazon Linux 2
Product:
pidgin
libpurple
finch
Reference:
ALAS2-2023-2115
CVE-2022-26491
CVE    1
CVE-2022-26491

© SecPod Technologies