An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pidgin | Aug 22, 2024 | May 31, 2022 |
| Amazon Linux Ami 2 | — | Upgrade pidginUpgrade pidgin-perlUpgrade libpurple-develUpgrade libpurple-tclUpgrade pidgin-develUpgrade finch-develUpgrade libpurpleUpgrade finchUpgrade pidgin-debuginfoUpgrade libpurple-perl | Jul 21, 2023 | Jun 2, 2022 |
| Debian | — | Upgrade pidgin | Jun 8, 2022 | Jun 2, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libpurple | Aug 18, 2022 | Jun 2, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libpurple | Aug 18, 2022 | Jun 2, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2022 |
| Suse | — | Upgrade libpurple-langUpgrade libpurple-branding-upstreamUpgrade libpurple0Upgrade finch-develUpgrade pidgin-develUpgrade pidginUpgrade libpurple-plugin-sametimeUpgrade libpurple-tclUpgrade libpurple-develUpgrade libpurple-client0Upgrade finchUpgrade libpurple | Oct 26, 2022 | Jun 2, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub