Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 234135
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 234135 depends on: Show dependency tree
Bug 234135 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-08-06 22:26 0000
Secunia writes:
A security issue has been reported in Pidgin, which can be exploited
by malicious people to conduct spoofing attacks.

The problem is that the certificate presented by e.g. a Jabber server
at the beginning of an SSL session is not verified. This can be
exploited to spoof valid servers via a man-in-the-middle attack.

Successful exploitation requires that Pidgin is configured to use the
NSS plugin.

The security issue is reported in version 2.4.3. Other versions may
also be affected.

SOLUTION:
Do not rely on the application's SSL certificate verification.

PROVIDED AND/OR DISCOVERED BY:
Reported by Josh Triplett in a Debian bug report.

ORIGINAL ADVISORY:
http://developer.pidgin.im/ticket/6500

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434

------- Comment #1 From David King 2008-08-20 14:55:35 0000 -------
This issue is fixed in 2.5.0, which is in the portage tree but currently marked
unstable.

------- Comment #2 From Olivier Crete 2008-08-20 16:32:24 0000 -------
The ebuild is in. I'm a bit shy about rushing this to stable because its not a
great threat and there is a whole new MSN implementation in that version and
I'm not sure how good it is.

------- Comment #3 From Robert Buchholz 2008-08-20 20:22:21 0000 -------
We could argue about the impact of failure to verify certificates, especially
when people rely on it. Let's give it the rest of this week in ~arch to test,
and we will CC arches on Aug. 24.
Please mark any bugs that come up as blockers of this bug.

------- Comment #4 From Pierre-Yves Rofes 2008-09-05 21:32:28 0000 -------
Arches, please test and mark stable net-im/pidgin-2.5.1. Target Keywords:
"alpha amd64 hppa ia64 ppc ~ppc64 sparc x86 ~x86-fbsd"

------- Comment #5 From Ferris McCormick 2008-09-05 23:39:57 0000 -------
Sparc stable for pidgin-2.5.1.

------- Comment #6 From Markus Meier 2008-09-06 12:39:33 0000 -------
amd64/x86 stable

------- Comment #7 From Raúl Porcel 2008-09-06 15:56:45 0000 -------
alpha/ia64 stable

------- Comment #8 From Tobias Scherbaum 2008-09-06 21:40:36 0000 -------
ppc stable

------- Comment #9 From Jeroen Roovers 2008-09-08 03:12:24 0000 -------
Stable for HPPA.

------- Comment #10 From DEMAINE Benoît-Pierre, aka DoubleHP 2008-09-10 01:47:39 0000 -------
2.5.1 is now in x86 stable and merged to Portage; if all other arch, i think
you can close this bug ... 

------- Comment #11 From Tobias Heinlein 2008-09-11 17:34:40 0000 -------
(In reply to comment #10)
> 2.5.1 is now in x86 stable and merged to Portage; if all other arch, i think
> you can close this bug ... 
> 

Thanks for your effort, but ... no, not really. This is a security bug, please
see our policy[1].

So, ready for voting. I vote YES.


[1] http://www.gentoo.org/security/en/vulnerability-policy.xml

------- Comment #12 From Pierre-Yves Rofes 2008-09-18 21:50:27 0000 -------
voting yes too, request filed.

------- Comment #13 From Pierre-Yves Rofes 2009-01-20 22:08:01 0000 -------
GLSA 200901-13, sorry for the delay

------- Comment #14 From DEMAINE Benoît-Pierre, aka DoubleHP 2009-01-21 00:49:59 0000 -------
2.5.2 stable by now, and 2.5.4 should come in withint 24h (bump request just
closed, waiting for tree to sync).

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug