Full Disclosure mailing list archives
Re: pidgin OTR information leakage
From: Dimitris Glynos <dimitris () census gr>
Date: Sun, 26 Feb 2012 13:44:18 +0200
On 02/25/2012 06:31 PM, Dimitris Glynos wrote:
Pidgin transmits OTR (off-the-record) conversations over DBUS in plaintext. This makes it possible for attackers that have gained user-level access on a host, to listen in on private conversations associated with the victim account.
As noted by Peter Lawler this should really be referenced as a libpurple issue and not a pidgin one. You may find the updated advisory here: http://census-labs.com/news/2012/02/25/libpurple-otr-info-leak/ (old URL is valid too) Best regards, Dimitris Glynos -- http://census-labs.com -- IT security research, development and services _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- pidgin OTR information leakage Dimitris Glynos (Feb 27)
- Re: pidgin OTR information leakage Dimitris Glynos (Feb 27)
- Re: pidgin OTR information leakage Jann Horn (Feb 27)
- Re: pidgin OTR information leakage Michele Orru (Feb 27)
- Re: pidgin OTR information leakage Rich Pieri (Feb 28)
- Re: pidgin OTR information leakage Jeffrey Walton (Feb 27)
- Re: pidgin OTR information leakage Ferenc Kovacs (Feb 27)
- Message not available
- Re: pidgin OTR information leakage Dimitris Glynos (Feb 28)
- Re: pidgin OTR information leakage Michele Orru (Feb 27)
- <Possible follow-ups>
- Re: pidgin OTR information leakage Dimitris Glynos (Feb 28)
