protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-08-31T20:00:00

Updated: 2024-08-07T06:14:55.553Z

Reserved: 2009-08-31T00:00:00

Link: CVE-2009-3026

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-08-31T20:30:01.140

Modified: 2017-09-19T01:29:24.873

Link: CVE-2009-3026

cve-icon Redhat

Severity : Low

Publid Date: 2009-01-15T00:00:00Z

Links: CVE-2009-3026 - Bugzilla