Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2008-3532

Published: 8 August 2008

The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.

Notes

AuthorNote
mdeslaur
In dapper, nss is not compiled in

Priority

Low

Status

Package Release Status
gaim
Launchpad, Ubuntu, Debian
dapper Not vulnerable
(1:1.5.0+1.5.1cvs20051015-1ubuntu10)
feisty Ignored
(end of life, was needed)
gutsy Does not exist

hardy Does not exist

intrepid Does not exist

upstream
Released (2.4.3-2)
pidgin
Launchpad, Ubuntu, Debian
dapper Does not exist

feisty Does not exist

gutsy
Released (1:2.2.1-1ubuntu4.3)
hardy
Released (1:2.4.1-1ubuntu2.2)
intrepid Not vulnerable
(1:2.5.2-0ubuntu1)
upstream
Released (2.4.3-2)
Patches:
other: http://developer.pidgin.im/ticket/6500
upstream: http://developer.pidgin.im/viewmtn/revision/info/ad677f4ab3dcd31d42fe39edbb9e9207dcf93df6
upstream: http://developer.pidgin.im/viewmtn/revision/info/3cbc74478c8df61d53804d0363dc936a3e0adeb7