Bugzilla – Bug 991721
VUL-0: CVE-2016-2379: pidgin: hash password recovery
Last modified: 2016-08-02 13:53:32 UTC
CVE-2016-2379 https://www.pidgin.im/news/security/?id=95 Pidgin Security Advisory Title Date 2016-06-21 CVE Name CVE 2016-2379 Discovered By Yves Younan of Cisco Talos Description An attacker who eavesdrops on a Mxit session captures the user's hashed password. The hashed password can be re-used to login as that user. (TALOS-CAN-0122) Fixed in Version Fix N/A. This is a fundamental problem with the Mxit protocol. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2379
pidgin says it is a problem of the MXIT protocol and can not be fixed.