5
CVSSv2

CVE-2009-1375

Published: 26/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The PurpleCircBuffer implementation in Pidgin (formerly Gaim) prior to 2.5.6 does not properly maintain a certain buffer, which allows remote malicious users to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.1.1

pidgin pidgin 2.0.1

pidgin pidgin 2.3.1

pidgin pidgin 2.1.0

pidgin pidgin 2.5.3

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.0.2

pidgin pidgin 2.0.0

pidgin pidgin 2.3.0

pidgin pidgin 2.2.1

pidgin pidgin 2.5.0

pidgin pidgin 2.4.0

pidgin pidgin 2.4.1

pidgin pidgin 2.2.2

pidgin pidgin 2.4.3

pidgin pidgin 2.2.0

pidgin pidgin 2.4.2

pidgin pidgin

pidgin pidgin 2.5.4

Vendor Advisories

Synopsis Important: pidgin security update Type/Severity Security Advisory: Important Topic Updated pidgin packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having important security impact by the RedHat Security Response Team ...
It was discovered that Pidgin did not properly handle certain malformed messages when sending a file using the XMPP protocol handler If a user were tricked into sending a file, a remote attacker could send a specially crafted response and cause Pidgin to crash, or possibly execute arbitrary code with user privileges (CVE-2009-1373) ...
Several vulnerabilities have been discovered in Pidgin, a graphical multi-protocol instant messaging client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1373 A buffer overflow in the Jabber file transfer code may lead to denial of service or the execution of arbitrary code CVE-2009-1375 ...