4.3
CVSSv2

CVE-2013-6478

Published: 06/02/2014 Updated: 16/03/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

gtkimhtml.c in Pidgin prior to 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote malicious users to cause a denial of service (application crash) via a long URL that is examined with a tooltip.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin 2.7.8

pidgin pidgin 2.7.7

pidgin pidgin 2.7.10

pidgin pidgin 2.7.1

pidgin pidgin 2.6.1

pidgin pidgin 2.6.0

pidgin pidgin 2.5.2

pidgin pidgin 2.5.1

pidgin pidgin 2.3.0

pidgin pidgin 2.2.2

pidgin pidgin 2.10.2

pidgin pidgin 2.10.1

pidgin pidgin 2.10.0

pidgin pidgin 2.9.0

pidgin pidgin 2.7.4

pidgin pidgin 2.7.3

pidgin pidgin 2.6.5

pidgin pidgin 2.6.4

pidgin pidgin 2.5.6

pidgin pidgin 2.5.5

pidgin pidgin 2.4.2

pidgin pidgin 2.4.1

pidgin pidgin 2.10.6

pidgin pidgin 2.10.5

pidgin pidgin 2.0.2

pidgin pidgin 2.0.1

pidgin pidgin 2.8.0

pidgin pidgin 2.7.9

pidgin pidgin 2.7.2

pidgin pidgin 2.7.11

pidgin pidgin 2.6.3

pidgin pidgin 2.6.2

pidgin pidgin 2.5.4

pidgin pidgin 2.5.3

pidgin pidgin 2.4.0

pidgin pidgin 2.3.1

pidgin pidgin 2.10.4

pidgin pidgin 2.10.3

pidgin pidgin 2.0.0

pidgin pidgin

pidgin pidgin 2.7.6

pidgin pidgin 2.7.5

pidgin pidgin 2.7.0

pidgin pidgin 2.6.6

pidgin pidgin 2.5.9

pidgin pidgin 2.5.8

pidgin pidgin 2.5.7

pidgin pidgin 2.5.0

pidgin pidgin 2.4.3

pidgin pidgin 2.2.1

pidgin pidgin 2.2.0

pidgin pidgin 2.1.1

pidgin pidgin 2.1.0

Vendor Advisories

Several security issues were fixed in Pidgin ...
Multiple vulnerabilities have been discovered in Pidgin, a multi-protocol instant messaging client: CVE-2013-6477 Jaime Breva Ribes discovered that a remote XMPP user can trigger a crash by sending a message with a timestamp in the distant future CVE-2013-6478 Pidgin could be crashed through overly wide tooltip windows CVE-2013-6479 ...
gtkimhtmlc in Pidgin before 2108 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (application crash) via a long URL that is examined with a tooltip ...