CVE-2008-3532
The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service.
- Affected products
- Nss, Red Hat, Libpurple, Libpurple-Devel, Libpurple-Tcl
- Pidgin
- = 2.4.3
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 1.6% (74th percentile)
- Weakness
- CWE-310
- NVD status
- Modified
- Published
- 2008-08-08
CVE-2008-3532 at NVD
No indexed exploits for CVE-2008-3532 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2008-3532 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.