7.1
CVSSv2

CVE-2009-1373

Published: 26/05/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.1 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 632
Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) prior to 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.1.0

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.0.1

pidgin pidgin 2.4.2

pidgin pidgin 2.5.4

pidgin pidgin 2.2.2

pidgin pidgin 2.1.1

pidgin pidgin 2.3.1

pidgin pidgin 2.4.3

pidgin pidgin 2.0.0

pidgin pidgin 2.0.2

pidgin pidgin 2.3.0

pidgin pidgin 2.4.1

pidgin pidgin 2.4.0

pidgin pidgin

pidgin pidgin 2.5.0

pidgin pidgin 2.2.0

pidgin pidgin 2.2.1

pidgin pidgin 2.5.3

Vendor Advisories

Synopsis Important: pidgin security update Type/Severity Security Advisory: Important Topic Updated pidgin packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having important security impact by the RedHat Security Response Team ...
Synopsis Important: pidgin security update Type/Severity Security Advisory: Important Topic An updated pidgin package that fixes two security issues is now availablefor Red Hat Enterprise Linux 3This update has been rated as having important security impact by the RedHat Security Response Team De ...
It was discovered that Gaim did not properly handle certain malformed messages when sending a file using the XMPP protocol handler If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Gaim to crash, or possibly execute arbitrary code with user privileges (CVE-2009-1373) ...
It was discovered that Pidgin did not properly handle certain malformed messages when sending a file using the XMPP protocol handler If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Pidgin to crash, or possibly execute arbitrary code with user privileges (CVE-2009-1373) ...
Several vulnerabilities have been discovered in Pidgin, a graphical multi-protocol instant messaging client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1373 A buffer overflow in the Jabber file transfer code may lead to denial of service or the execution of arbitrary code CVE-2009-1375 ...