An out-of-bounds write has been found in libpurple < 2.12.0 in the purple_markup_unescape_entity function. This issue can be triggered by a malicious server sending invalid XML entities separated by whitespace, eg "ஸ" to the client.
An out-of-bounds write has been found in libpurple < 2.12.0 in the purple_markup_unescape_entity function. This issue can be triggered by a malicious server sending invalid XML entities separated by whitespace, eg "ஸ" to the client.
http://seclists.org/fulldisclosure/2017/Mar/57 https://www.pidgin.im/news/security/?id=109 https://bitbucket.org/pidgin/main/commits/b2fc9e774cb9