CVE-2014-3694
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows…
Does this matter?
Lower severity and a low EPSS score (2.35%). Track it; it rarely justifies an emergency change on its own.
Description
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- opensuse/opensuse · canonical/ubuntu linux · debian/debian linux · pidgin/pidgin
- Source
- secalert@redhat.com
References
- http://hg.pidgin.im/pidgin/main/rev/2e4475087f04Issue Tracking
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00023.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00037.htmlThird Party Advisory
- http://pidgin.im/news/security/?id=86Patch, Vendor Advisory
- http://secunia.com/advisories/60741
- http://secunia.com/advisories/61968
- http://www.debian.org/security/2014/dsa-3055Third Party Advisory
- http://www.ubuntu.com/usn/USN-2390-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1854
- http://hg.pidgin.im/pidgin/main/rev/2e4475087f04Issue Tracking
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00023.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00037.htmlThird Party Advisory
- http://pidgin.im/news/security/?id=86Patch, Vendor Advisory
- http://secunia.com/advisories/60741
- http://secunia.com/advisories/61968
- http://www.debian.org/security/2014/dsa-3055Third Party Advisory
- http://www.ubuntu.com/usn/USN-2390-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1854
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.