CVE-2014-3694
Publication date 23 October 2014
Last updated 24 July 2024
Ubuntu priority
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Status
Package | Ubuntu Release | Status |
---|---|---|
pidgin | ||
14.04 LTS trusty |
Fixed 1:2.10.9-0ubuntu3.2
|
|
Patch details
Package | Patch details |
---|---|
pidgin |
References
Related Ubuntu Security Notices (USN)
- USN-2390-1
- Pidgin vulnerabilities
- 28 October 2014