The problem is caused by the fix for CVE-2011-3389: <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389> <https://bugzilla.mozilla.org/show_bug.cgi?id=665814> <https://bugzilla.mozilla.org/show_bug.cgi?id=702111>
Microsoft Lync servers seem to be one of the SSL servers that don't like the 1/n-1 record splitting. Workaround: set environment variable NSS_SSL_CBC_RANDOM_IV=0 when running Pidgin.