CVE-2014-3694

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
opensuseopensuse
12.3
opensuseopensuse
13.1
opensuseopensuse
13.2
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
debiandebian_linux
7.0
pidginpidgin
𝑥
≤ 2.10.9
pidginpidgin
2.10.0
pidginpidgin
2.10.1
pidginpidgin
2.10.2
pidginpidgin
2.10.3
pidginpidgin
2.10.4
pidginpidgin
2.10.5
pidginpidgin
2.10.6
pidginpidgin
2.10.7
pidginpidgin
2.10.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pidgin
bookworm
2.14.12-1
fixed
bullseye
2.14.1-1
fixed
sid
2.14.13-2
fixed
trixie
2.14.13-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pidgin
lucid
ignored
precise
Fixed 1:2.10.3-0ubuntu1.6
released
trusty
Fixed 1:2.10.9-0ubuntu3.2
released
utopic
Fixed 1:2.10.9-0ubuntu7.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
finch
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
libpurple
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-branding-upstream
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-client0
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-devel
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-lang
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-meanwhile
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
libpurple-plugin-sametime
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-tcl
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
libpurple0
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
pidgin
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
pidgin-devel
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
finch
RHEL 7
0:2.10.11-5.el7
fixed
finch-devel
RHEL 7
0:2.10.11-5.el7
fixed
libpurple
RHEL 7
0:2.10.11-5.el7
fixed
libpurple-devel
RHEL 7
0:2.10.11-5.el7
fixed
libpurple-perl
RHEL 7
0:2.10.11-5.el7
fixed
libpurple-tcl
RHEL 7
0:2.10.11-5.el7
fixed
pidgin
RHEL 7
0:2.10.11-5.el7
fixed
pidgin-devel
RHEL 7
0:2.10.11-5.el7
fixed
pidgin-perl
RHEL 7
0:2.10.11-5.el7
fixed
Common Weakness Enumeration