Bugzilla – Bug 989989
VUL-0: CVE-2016-1000030: pidgin: X.509 Certificates improperly imported
Last modified: 2018-06-11 14:45:44 UTC
rh#1348882 X.509 certificates may be improperly imported when using GnuTLS. Fix: https://bitbucket.org/pidgin/main/commits/d6fc1ce76ffe References: http://www.pidgin.im/news/security/?id=91 https://bugzilla.redhat.com/show_bug.cgi?id=1348882 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1000030
vulnerability confirmed on SLE12 but not SLE11. Will work on it.
(In reply to Felix Zhang from comment #1) > vulnerability confirmed on SLE12 but not SLE11. Will work on it. Correct to myself. The vulnerability is fixed in pidgin 2.11.0. Which has been pushed to SUSE:SLE-12-SP2:GA
As in previous comment. SLE11 and SLE12SP2 are not affected.
(In reply to Felix Zhang from comment #3) then we can close this, fixed in current products