6.4
CVSSv2

CVE-2011-4939

Published: 15/03/2012 Updated: 18/01/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin prior to 2.10.2 allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.9.0

pidgin pidgin 2.8.0

pidgin pidgin 2.7.5

pidgin pidgin 2.7.4

pidgin pidgin 2.6.2

pidgin pidgin 2.6.1

pidgin pidgin 2.5.4

pidgin pidgin 2.5.3

pidgin pidgin 2.4.0

pidgin pidgin 2.3.1

pidgin pidgin 2.0.1

pidgin pidgin 2.0.0

pidgin pidgin 2.7.9

pidgin pidgin 2.7.8

pidgin pidgin 2.7.1

pidgin pidgin 2.6.6

pidgin pidgin 2.6.5

pidgin pidgin 2.5.8

pidgin pidgin 2.5.7

pidgin pidgin 2.5.0

pidgin pidgin 2.4.3

pidgin pidgin 2.2.0

pidgin pidgin 2.1.1

pidgin pidgin 2.7.11

pidgin pidgin 2.7.10

pidgin pidgin 2.7.3

pidgin pidgin 2.7.2

pidgin pidgin 2.6.0

pidgin pidgin 2.5.9

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.3.0

pidgin pidgin 2.2.2

pidgin pidgin 2.2.1

pidgin pidgin

pidgin pidgin 2.10.0

pidgin pidgin 2.7.7

pidgin pidgin 2.7.6

pidgin pidgin 2.6.4

pidgin pidgin 2.6.3

pidgin pidgin 2.5.6

pidgin pidgin 2.5.5

pidgin pidgin 2.4.2

pidgin pidgin 2.4.1

pidgin pidgin 2.1.0

pidgin pidgin 2.0.2

Vendor Advisories

Several security issues were fixed in Pidgin ...
Debian Bug report logs - #664030 [CVE-2012-1178] pidgin: Possible MSN remote crash Package: pidgin; Maintainer for pidgin is Ari Pollak <ari@debianorg>; Source for pidgin is src:pidgin (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 14 Mar 2012 23:09:01 UTC Severity: grave Tags: pat ...
Debian Bug report logs - #664028 [CVE-2011-4939] pidgin: XMPP remote crash Package: pidgin; Maintainer for pidgin is Ari Pollak <ari@debianorg>; Source for pidgin is src:pidgin (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 14 Mar 2012 23:00:05 UTC Severity: grave Tags: patch, secu ...