PT-2008-1057 · Pidgin+2 · Libpurple+4

Published

2008-08-08

·

Updated

2024-06-15

·

CVE-2008-3532

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpurple versions 2.4.3 through 2.5.2 libpurple-devel versions 2.5.2 libpurple-tcl versions 2.5.2
Description The issue is related to multiple vulnerabilities in the libpurple package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the NSS plugin in libpurple does not verify SSL certificates, making it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Recommendations For libpurple versions 2.4.3 through 2.5.2, consider disabling the SSL verification function until a patch is available. For libpurple-devel versions 2.5.2, restrict access to the vulnerable package to minimize the risk of exploitation. For libpurple-tcl versions 2.5.2, avoid using the vulnerable package in production environments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06318
BDU:2015-06320
BDU:2015-06322
CVE-2008-3532
OPENSUSE-SU-2024:11172-1
RHSA-2008:1023
RHSA-2008_1023

Affected Products

Nss
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl