Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pidgin libpurple库不安全连接漏洞
Vulnerability Description
Pidgin是一款跨平台的实时通信客户端,它支持多个常用的实时通信协议,用户可用同一个软件登录不同的实时通信服务。 在连接到不遵循XMPP规范的老式Jabber服务器时Pidgin所使用的libpurple库中的protocols/jabber/auth.c文件没有强制"require TLS/SSL"偏好选项,TLS/SSL连接已经失败但libpurple库仍会未经加密便连接到服务器。远程攻击者可以从不安全的连接中嗅探会话。
CVSS Information
N/A
Vulnerability Type
N/A