7.5
CVSSv2

CVE-2012-2369

Published: 23/05/2012 Updated: 06/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin prior to 3.2.1 for Pidgin might allow remote malicious users to execute arbitrary code via format string specifiers in data that generates a log message.

Vulnerable Product Search on Vulmon Subscribe to Product

cypherpunks pidgin-otr

Vendor Advisories

Debian Bug report logs - #673154 CVE-2012-2369: Format string security vulnerability Package: pidgin-otr; Maintainer for pidgin-otr is Debian Privacy Tools Maintainers <pkg-privacy-maintainers@listsaliothdebianorg>; Source for pidgin-otr is src:pidgin-otr (PTS, buildd, popcon) Reported by: Jonathan Wiltshire <jmw@debia ...