5
CVSSv2

CVE-2009-1374

Published: 26/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) prior to 2.5.6 allows remote malicious users to cause a denial of service (application crash) via a QQ packet.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.0.0

pidgin pidgin 2.4.0

pidgin pidgin 2.2.1

pidgin pidgin 2.2.2

pidgin pidgin 2.4.1

pidgin pidgin 2.2.0

pidgin pidgin 2.0.2

pidgin pidgin

pidgin pidgin 2.4.3

pidgin pidgin 2.1.1

pidgin pidgin 2.4.2

pidgin pidgin 2.3.1

pidgin pidgin 2.5.4

pidgin pidgin 2.5.3

pidgin pidgin 2.0.1

pidgin pidgin 2.1.0

pidgin pidgin 2.3.0

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.5.0

Vendor Advisories

Synopsis Important: pidgin security update Type/Severity Security Advisory: Important Topic Updated pidgin packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having important security impact by the RedHat Security Response Team ...
It was discovered that Pidgin did not properly handle certain malformed messages when sending a file using the XMPP protocol handler If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Pidgin to crash, or possibly execute arbitrary code with user privileges (CVE-2009-1373) ...