Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
http://pidgin.im/pipermail/devel/2011-December/010521.html | vendor advisory |
http://developer.pidgin.im/ticket/14830 | vendor advisory |