4
CVSSv2

CVE-2011-1091

Published: 14/03/2011 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 up to and including 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.7.9

pidgin pidgin 2.7.5

pidgin pidgin 2.7.0

pidgin pidgin 2.7.4

pidgin pidgin 2.6.0

pidgin pidgin 2.7.6

pidgin pidgin 2.7.10

pidgin pidgin 2.7.3

pidgin pidgin 2.6.5

pidgin pidgin 2.6.6

pidgin pidgin 2.6.2

pidgin pidgin 2.7.8

pidgin pidgin 2.7.7

pidgin pidgin 2.6.1

pidgin pidgin 2.6.4

pidgin pidgin 2.7.2

pidgin pidgin 2.7.1

Vendor Advisories

Pidgin could be made to crash if it received specially crafted network traffic ...