5
CVSSv2

CVE-2009-3084

Published: 08/09/2009 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin prior to 2.6.2, allows remote malicious users to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.5.9

pidgin pidgin 2.4.1

pidgin pidgin 2.4.0

pidgin pidgin 2.4.2

pidgin pidgin 2.4.3

pidgin pidgin 2.5.1

pidgin pidgin 2.5.5

pidgin pidgin 2.1.0

pidgin pidgin 2.5.7

pidgin pidgin 2.0.1

pidgin pidgin 2.5.4

pidgin pidgin 2.3.0

pidgin pidgin 2.2.2

pidgin pidgin 2.5.2

pidgin pidgin 2.0.2

pidgin pidgin 2.6.0

pidgin pidgin 2.0.0

pidgin pidgin 2.5.0

pidgin pidgin 2.5.8

pidgin pidgin 2.5.3

pidgin pidgin 2.2.0

pidgin pidgin 2.5.6

pidgin pidgin 2.1.1

pidgin pidgin 2.3.1

pidgin pidgin 2.2.1

pidgin pidgin

pidgin libpurple 2.6.1

pidgin libpurple 2.6.0

Vendor Advisories

Debian Bug report logs - #566775 pidgin: CVE-2010-0277 denial-of-service Package: pidgin; Maintainer for pidgin is Ari Pollak <ari@debianorg>; Source for pidgin is src:pidgin (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Mon, 25 Jan 2010 02:21:01 UTC Severity: important Tags ...