PT-2008-1057 · Pidgin+2 · Libpurple+4
Published
2008-08-08
·
Updated
2024-06-15
·
CVE-2008-3532
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libpurple versions 2.4.3 through 2.5.2
libpurple-devel versions 2.5.2
libpurple-tcl versions 2.5.2
Description
The issue is related to multiple vulnerabilities in the libpurple package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the NSS plugin in libpurple does not verify SSL certificates, making it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Recommendations
For libpurple versions 2.4.3 through 2.5.2, consider disabling the SSL verification function until a patch is available.
For libpurple-devel versions 2.5.2, restrict access to the vulnerable package to minimize the risk of exploitation.
For libpurple-tcl versions 2.5.2, avoid using the vulnerable package in production environments until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nss
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl