5
CVSSv2

CVE-2009-3083

Published: 08/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin prior to 2.6.2 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin libpurple

pidgin pidgin 2.5.9

pidgin pidgin 2.4.3

pidgin pidgin 2.4.1

pidgin pidgin 2.4.2

pidgin pidgin 2.0.0

pidgin pidgin 2.4.0

pidgin pidgin 2.5.2

pidgin pidgin 2.5.0

pidgin pidgin 2.5.1

pidgin pidgin 2.5.6

pidgin pidgin 2.1.0

pidgin pidgin 2.5.5

pidgin pidgin 2.5.3

pidgin pidgin 2.5.7

pidgin pidgin 2.2.1

pidgin pidgin 2.5.4

pidgin pidgin 2.2.2

pidgin pidgin 2.5.8

pidgin pidgin 2.0.2

pidgin pidgin 2.2.0

pidgin pidgin 2.1.1

pidgin pidgin 2.0.1

pidgin pidgin 2.3.1

pidgin pidgin 2.3.0

pidgin pidgin 2.6.0

pidgin pidgin

Vendor Advisories

Debian Bug report logs - #566775 pidgin: CVE-2010-0277 denial-of-service Package: pidgin; Maintainer for pidgin is Ari Pollak <ari@debianorg>; Source for pidgin is src:pidgin (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Mon, 25 Jan 2010 02:21:01 UTC Severity: important Tags ...
It was discovered that Pidgin did not properly handle certain topic messages in the IRC protocol handler If a user were tricked into connecting to a malicious IRC server, an attacker could cause Pidgin to crash, leading to a denial of service This issue only affected Ubuntu 804 LTS, Ubuntu 810 and Ubuntu 904 (CVE-2009-2703) ...