Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <200908241910.49783.steffen.joeris@skolelinux.de>
Date: Mon, 24 Aug 2009 19:10:45 +1000
From: Steffen Joeris <steffen.joeris@...lelinux.de>
To: "oss-security" <oss-security@...ts.openwall.com>,
 coley <coley@...re.org>
Subject: CVE id request: pidgin

Hi

There seems to be another issue with pidgin. It does not enforce SSL/TLS and 
seems to connect without encryption, although the box is ticked.

See Debian Bug here:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891

This upstream commit was pointed out to me:
http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279

Reporter promised to check whether gaim is affected too, so I guess the 
bugreport will be updated.

Could I please get a CVE id for this?

Cheers
Steffen

Download attachment "signature.asc " of type "application/pgp-signature" (198 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.