cbcvebase.
CVE-2014-3694
published 2014-10-29

CVE-2014-3694: The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic…

PriorityP429medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.35%
81.8th percentile
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected

23 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianpidgin< pidgin 2.10.10-1 (bookworm)pidgin 2.10.10-1 (bookworm)
opensuseopensuse
opensuseopensuse
opensuseopensuse
pidginpidgin<= 2.10.9
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin
pidginpidgin>= 0 < 2.10.10-12.10.10-1
pidginpidgin>= 0 < 2.10.10-12.10.10-1
pidginpidgin>= 0 < 2.10.10-12.10.10-1
pidginpidgin>= 0 < 2.10.10-12.10.10-1
pidginpidgin>= 0 < 1:2.10.9-0ubuntu3.21:2.10.9-0ubuntu3.2

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.