CVE-2008-3532
published 2008-08-08CVE-2008-3532: The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.64%
73.7th percentile
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.4.3-2 (bookworm) | pidgin 2.4.3-2 (bookworm) |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.4.3-2 | 2.4.3-2 |
| pidgin | pidgin | >= 0 < 2.4.3-2 | 2.4.3-2 |
| pidgin | pidgin | >= 0 < 2.4.3-2 | 2.4.3-2 |
| pidgin | pidgin | >= 0 < 2.4.3-2 | 2.4.3-2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2008-11-24·CVSS 6.8
CVE-2008-2927 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
It was discovered that Pidgin did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a specially
crafted message and possibly execute arbitrary code with user privileges.
(CVE-2008-2927)
It was discovered that Pidgin did not properly handle file transfers containing
a long filename and special characters in the MSN protocol handler. A remote
attacker could send a specially crafted filename in a file transfer request
and cause Pidgin to crash, leading to a denial of service. (CVE-2008-2955)
It was discovered that Pidgin did not impose resource limitations in the UPnP
service. A remote attacker could cause Pidgin to download arbitrary files
and cause a denial of service fro
Red Hat
pidgin: NSS plugin doesn't verify SSL certificates
vendor_redhat·2008-07-28·CVSS 6.8
CVE-2008-3532 [MEDIUM] pidgin: NSS plugin doesn't verify SSL certificates
pidgin: NSS plugin doesn't verify SSL certificates
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Debian
CVE-2008-3532: pidgin - The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, wh...
vendor_debian·2008·CVSS 6.8
CVE-2008-3532 [MEDIUM] CVE-2008-3532: pidgin - The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, wh...
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Scope: local
bookworm: resolved (fixed in 2.4.3-2)
bullseye: resolved (fixed in 2.4.3-2)
forky: resolved (fixed in 2.4.3-2)
sid: resolved (fixed in 2.4.3-2)
trixie: resolved (fixed in 2.4.3-2)
GHSA
GHSA-ww4m-hgqp-q9hp: The NSS plugin in libpurple in Pidgin 2
ghsa_unreviewed·2022-05-02
CVE-2008-3532 [MEDIUM] GHSA-ww4m-hgqp-q9hp: The NSS plugin in libpurple in Pidgin 2
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
OSV
CVE-2008-3532: The NSS plugin in libpurple in Pidgin 2
osv·2008-08-08·CVSS 6.8
CVE-2008-3532 [MEDIUM] CVE-2008-3532: The NSS plugin in libpurple in Pidgin 2
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434http://developer.pidgin.im/attachment/ticket/6500/nss-cert-verify.patchhttp://developer.pidgin.im/attachment/ticket/6500/nss_add_rev.patchhttp://developer.pidgin.im/ticket/6500http://secunia.com/advisories/31390http://secunia.com/advisories/32859http://secunia.com/advisories/33102http://support.avaya.com/elmodocs2/security/ASA-2008-493.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:025http://www.redhat.com/support/errata/RHSA-2008-1023.htmlhttp://www.securityfocus.com/bid/30553http://www.ubuntu.com/usn/USN-675-1http://www.vupen.com/english/advisories/2008/2318https://exchange.xforce.ibmcloud.com/vulnerabilities/44220https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18327http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434http://developer.pidgin.im/attachment/ticket/6500/nss-cert-verify.patchhttp://developer.pidgin.im/attachment/ticket/6500/nss_add_rev.patchhttp://developer.pidgin.im/ticket/6500http://secunia.com/advisories/31390http://secunia.com/advisories/32859http://secunia.com/advisories/33102http://support.avaya.com/elmodocs2/security/ASA-2008-493.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:025http://www.redhat.com/support/errata/RHSA-2008-1023.htmlhttp://www.securityfocus.com/bid/30553http://www.ubuntu.com/usn/USN-675-1http://www.vupen.com/english/advisories/2008/2318https://exchange.xforce.ibmcloud.com/vulnerabilities/44220https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18327
2008-08-08
Published