|
Message-Id: <200908241910.49783.steffen.joeris@skolelinux.de>
Date: Mon, 24 Aug 2009 19:10:45 +1000
From: Steffen Joeris <steffen.joeris@...lelinux.de>
To: "oss-security" <oss-security@...ts.openwall.com>,
coley <coley@...re.org>
Subject: CVE id request: pidgin
Hi
There seems to be another issue with pidgin. It does not enforce SSL/TLS and
seems to connect without encryption, although the box is ticked.
See Debian Bug here:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891
This upstream commit was pointed out to me:
http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279
Reporter promised to check whether gaim is affected too, so I guess the
bugreport will be updated.
Could I please get a CVE id for this?
Cheers
Steffen
Download attachment "signature.asc " of type "application/pgp-signature" (198 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.