5
CVSSv2

CVE-2009-3615

Published: 20/10/2009 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The OSCAR protocol plugin in libpurple in Pidgin prior to 2.6.3 and Adium prior to 1.3.7 allows remote malicious users to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.

Vulnerable Product Search on Vulmon Subscribe to Product

adium adium 1.3.3

adium adium 1.3.4

adium adium 1.0.3

adium adium 1.3

adium adium 1.1.3

pidgin pidgin 2.6.1

pidgin pidgin 2.5.4

pidgin pidgin 2.5.3

pidgin pidgin 2.3.1

pidgin pidgin 2.3.0

pidgin pidgin 2.0.1

pidgin pidgin 2.0.0

adium adium 1.3.5

adium adium 1.0

adium adium 1.0.4

adium adium 1.1

pidgin pidgin 2.6.0

pidgin pidgin 2.5.9

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.2.2

pidgin pidgin 2.2.1

adium adium

pidgin pidgin

adium adium 1.3.2

adium adium 1.2.7

adium adium 1.1.1

adium adium 1.1.4

pidgin pidgin 2.5.6

pidgin pidgin 2.5.5

pidgin pidgin 2.4.1

pidgin pidgin 2.4.0

pidgin pidgin 2.1.0

pidgin pidgin 2.0.2

adium adium 1.0.1

adium adium 1.3.1

adium adium 1.0.2

adium adium 1.0.5

adium adium 1.1.2

pidgin pidgin 2.5.8

pidgin pidgin 2.5.7

pidgin pidgin 2.5.0

pidgin pidgin 2.4.3

pidgin pidgin 2.4.2

pidgin pidgin 2.2.0

pidgin pidgin 2.1.1

Vendor Advisories

It was discovered that Pidgin did not properly handle certain topic messages in the IRC protocol handler If a user were tricked into connecting to a malicious IRC server, an attacker could cause Pidgin to crash, leading to a denial of service This issue only affected Ubuntu 804 LTS, Ubuntu 810 and Ubuntu 904 (CVE-2009-2703) ...