[Pidgin] #4570: The XMPP plugin uses the hostname given by the SRV record to perform certificate validation

Pidgin trac at pidgin.im
Sat Jan 5 11:00:30 EST 2008


#4570: The XMPP plugin uses the hostname given by the SRV record to perform
certificate validation
----------------------+-----------------------------------------------------
  Reporter:  steffen  |       Owner:  nwalp
      Type:  defect   |      Status:  new  
  Priority:  minor    |   Milestone:       
 Component:  XMPP     |     Version:  2.3.1
Resolution:           |    Keywords:       
   Pending:  1        |  
----------------------+-----------------------------------------------------
Changes (by rlaager):

  * pending:  0 => 1

Comment:

 If an attacker controls the DNS of that domain, I think you've lost.

-- 
Ticket URL: <http://developer.pidgin.im/ticket/4570#comment:1>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list