Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 24 Aug 2009 19:10:45 +1000
From: Steffen Joeris <steffen.joeris@...lelinux.de>
To: "oss-security" <oss-security@...ts.openwall.com>,
 coley <coley@...re.org>
Subject: CVE id request: pidgin

Hi

There seems to be another issue with pidgin. It does not enforce SSL/TLS and 
seems to connect without encryption, although the box is ticked.

See Debian Bug here:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891

This upstream commit was pointed out to me:
http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279

Reporter promised to check whether gaim is affected too, so I guess the 
bugreport will be updated.

Could I please get a CVE id for this?

Cheers
Steffen

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ