CVE-2008-3532
Publication date 8 August 2008
Last updated 24 July 2024
Ubuntu priority
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
Status
Package | Ubuntu Release | Status |
---|---|---|
gaim | 8.10 intrepid | Not in release |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty | Ignored end of life, was needed | |
6.06 LTS dapper |
Not affected
|
|
pidgin | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Fixed 1:2.4.1-1ubuntu2.2
|
|
7.10 gutsy |
Fixed 1:2.2.1-1ubuntu4.3
|
|
7.04 feisty | Not in release | |
6.06 LTS dapper | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
pidgin |