CVE-2009-3026
Summary
| CVE | CVE-2009-3026 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-31 20:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Gentoo update for pidgin - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | developer.pidgin.im | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| #542891 - libpurple connects without encryption while "require TLS/SSL" is enabled - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| oss-security - CVE id request: pidgin | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| #8131 (SSL/TLS bug due to old servers that don't follow xmpp spec) – Pidgin – Trac | af854a3a-2127-422b-91ae-364da2661108 | developer.pidgin.im | |
| Pidgin 'protocols/jabber/auth.c' JABBER Server XMPP Specifications Man In The Middle Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-22 | Mark J Cox | Red Hat has released updates to correct this issue: https://rhn.redhat.com/errata/RHSA-2009-1453.html |
There are currently no legacy QID mappings associated with this CVE.