5.9
CVSSv3

CVE-2022-26491

Published: 02/06/2022 Updated: 09/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Pidgin prior to 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the malicious user to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin

debian debian linux 9.0

Vendor Advisories

An issue was discovered in Pidgin before 2149 A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and ...