Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-26491
Description:An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.
Test IDs: 1.3.6.1.4.1.25623.1.0.893043   1.3.6.1.4.1.25623.1.0.127089   1.3.6.1.4.1.25623.1.1.2.2022.2277   1.3.6.1.4.1.25623.1.1.4.2022.1665.1   1.3.6.1.4.1.25623.1.1.10.2022.0208   1.3.6.1.4.1.25623.1.0.820486   1.3.6.1.4.1.25623.1.0.820646   1.3.6.1.4.1.25623.1.0.820551   1.3.6.1.4.1.25623.1.1.4.2022.1693.1   1.3.6.1.4.1.25623.1.1.13.2022.120.01   1.3.6.1.4.1.25623.1.0.127091   1.3.6.1.4.1.25623.1.1.2.2022.2230   1.3.6.1.4.1.25623.1.0.854634   1.3.6.1.4.1.25623.1.0.127090  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-26491
https://developer.pidgin.im/wiki/FullChangeLog
https://github.com/xsf/xeps/pull/1158
https://keep.imfreedom.org/pidgin/pidgin/rev/13cdb7956bdc
https://mail.jabber.org/pipermail/standards/2022-February/038759.html
https://pidgin.im/about/security/advisories/cve-2022-26491/
https://lists.debian.org/debian-lts-announce/2022/06/msg00005.html




© 1998-2025 E-Soft Inc. All rights reserved.