PT-2008-1057 · Pidgin+2 · Libpurple+4

Publicado

2008-08-08

·

Atualizado

2024-06-15

·

CVE-2008-3532

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpurple versions 2.4.3 through 2.5.2 libpurple-devel versions 2.5.2 libpurple-tcl versions 2.5.2
Description The issue is related to multiple vulnerabilities in the libpurple package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the NSS plugin in libpurple does not verify SSL certificates, making it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Recommendations For libpurple versions 2.4.3 through 2.5.2, consider disabling the SSL verification function until a patch is available. For libpurple-devel versions 2.5.2, restrict access to the vulnerable package to minimize the risk of exploitation. For libpurple-tcl versions 2.5.2, avoid using the vulnerable package in production environments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06318
BDU:2015-06320
BDU:2015-06322
CVE-2008-3532
OPENSUSE-SU-2024:11172-1
RHSA-2008:1023
RHSA-2008_1023

Produtos afetados

Nss
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl