PT-2016-4495 · Pidgin+1 · Pidgin+1

Publicado

2016-06-21

·

Atualizado

2018-11-14

·

CVE-2016-1000030

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pidgin versions prior to 2.11.0
Description The issue is related to improper checks of return values from gnutls x509 crt init() and gnutls x509 crt import() functions when importing X.509 certificates, potentially leading to code execution. This can be exploited via a custom X.509 certificate from another client.
Recommendations For versions prior to 2.11.0, update to version 2.11.0 to resolve the issue. As a temporary workaround, consider restricting the import of X.509 certificates from untrusted sources until the update is applied.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1727
CVE-2016-1000030

Produtos afetados

Alt Linux
Pidgin