Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 841611 (CVE-2022-26491) - <net-im/pidgin-2.14.9: MITM attack possible on non-DNSSEC XMPP connections
Summary: <net-im/pidgin-2.14.9: MITM attack possible on non-DNSSEC XMPP connections
Status: IN_PROGRESS
Alias: CVE-2022-26491
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on: 848579
Blocks:
  Show dependency tree
 
Reported: 2022-04-29 07:24 UTC by Sam James
Modified: 2023-01-09 09:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-04-29 07:24:30 UTC
Advisory: https://www.pidgin.im/about/security/advisories/cve-2022-26491/

From release notes:
"""
Security:
* Remove _xmppconnect support. (RR 1357) (CVE-2022-26491) (Gary
Kramlich)
"""
Comment 1 Larry the Git Cow gentoo-dev 2023-01-09 09:52:13 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=32cb1b90a7c0c79f060f2a2e6232450f3ebae8e6

commit 32cb1b90a7c0c79f060f2a2e6232450f3ebae8e6
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-01-09 09:51:35 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-01-09 09:52:06 +0000

    net-im/pidgin: drop 2.14.8, 2.14.9
    
    Bug: https://bugs.gentoo.org/841611
    Signed-off-by: Sam James <sam@gentoo.org>

 net-im/pidgin/Manifest                             |   2 -
 .../files/pidgin-2.14.8-libpurple_test_fix.patch   |  52 ----
 net-im/pidgin/pidgin-2.14.8.ebuild                 | 288 --------------------
 net-im/pidgin/pidgin-2.14.9.ebuild                 | 291 ---------------------
 4 files changed, 633 deletions(-)