CVE-2022-26491
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.
Se ha detectado un problema en Pidgin versiones anteriores a 2.14.9. Un atacante remoto que puede falsificar las respuestas DNS puede redirigir una conexión de cliente a un servidor malicioso. El cliente llevará a cabo la verificación del certificado TLS del nombre de dominio malicioso en lugar del dominio original del servicio XMPP, permitiendo al atacante tomar el control de la conexión XMPP y obtener las credenciales del usuario y todo el contenido de la comunicación. Esto es similar a CVE-2022-24968
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-06 CVE Reserved
- 2022-05-31 CVE Published
- 2023-12-22 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2022/06/msg00005.html | Mailing List | |
https://mail.jabber.org/pipermail/standards/2022-February/038759.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/xsf/xeps/pull/1158 | 2022-06-09 | |
https://keep.imfreedom.org/pidgin/pidgin/rev/13cdb7956bdc | 2022-06-09 |
URL | Date | SRC |
---|---|---|
https://developer.pidgin.im/wiki/FullChangeLog | 2022-06-09 | |
https://pidgin.im/about/security/advisories/cve-2022-26491 | 2022-06-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pidgin Search vendor "Pidgin" | Pidgin Search vendor "Pidgin" for product "Pidgin" | < 2.14.9 Search vendor "Pidgin" for product "Pidgin" and version " < 2.14.9" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|