VulnerabilityModified
CVE-2008-3532
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
MEDIUM 6.8EPSS 1.64%
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- pidgin/pidgin
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434
- http://developer.pidgin.im/attachment/ticket/6500/nss-cert-verify.patchExploit
- http://developer.pidgin.im/attachment/ticket/6500/nss_add_rev.patch
- http://developer.pidgin.im/ticket/6500Patch
- http://secunia.com/advisories/31390
- http://secunia.com/advisories/32859
- http://secunia.com/advisories/33102
- http://support.avaya.com/elmodocs2/security/ASA-2008-493.htm
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:025
- http://www.redhat.com/support/errata/RHSA-2008-1023.html
- http://www.securityfocus.com/bid/30553
- http://www.ubuntu.com/usn/USN-675-1
- http://www.vupen.com/english/advisories/2008/2318
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44220
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10979
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18327
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434
- http://developer.pidgin.im/attachment/ticket/6500/nss-cert-verify.patchExploit
- http://developer.pidgin.im/attachment/ticket/6500/nss_add_rev.patch
- http://developer.pidgin.im/ticket/6500Patch
- http://secunia.com/advisories/31390
- http://secunia.com/advisories/32859
- http://secunia.com/advisories/33102
- http://support.avaya.com/elmodocs2/security/ASA-2008-493.htm
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:025
- http://www.redhat.com/support/errata/RHSA-2008-1023.html
- http://www.securityfocus.com/bid/30553
- http://www.ubuntu.com/usn/USN-675-1
- http://www.vupen.com/english/advisories/2008/2318
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44220
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.