Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 24 Aug 2009 19:10:45 +1000
From: Steffen Joeris <>
To: "oss-security" <>,
 coley <>
Subject: CVE id request: pidgin


There seems to be another issue with pidgin. It does not enforce SSL/TLS and 
seems to connect without encryption, although the box is ticked.

See Debian Bug here:

This upstream commit was pointed out to me:

Reporter promised to check whether gaim is affected too, so I guess the 
bugreport will be updated.

Could I please get a CVE id for this?


Download attachment "signature.asc " of type "application/pgp-signature" (198 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.