Vulnerability identifier: #VU33911
Vulnerability risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-20
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Pidgin
Client/Desktop applications /
Messaging software
Vendor: pidgin.im
Description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Pidgin: 2.10.0 - 2.10.6
External links
https://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd
https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html
https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html
https://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html
https://www.pidgin.im/news/security/?id=67
https://www.ubuntu.com/usn/USN-1746-1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18340
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.