5
CVSSv2

CVE-2014-3695

Published: 29/10/2014 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

markup.c in the MXit protocol plugin in libpurple in Pidgin prior to 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin

pidgin pidgin 2.10.8

pidgin pidgin 2.10.1

pidgin pidgin 2.10.0

pidgin pidgin 2.10.3

pidgin pidgin 2.10.2

pidgin pidgin 2.10.7

pidgin pidgin 2.10.6

pidgin pidgin 2.10.5

pidgin pidgin 2.10.4

Vendor Advisories

Synopsis Moderate: pidgin security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for pidgin is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Several security issues were fixed in Pidgin ...
Multiple vulnerabilities have been discovered in Pidgin, a multi-protocol instant messaging client: CVE-2014-3694 It was discovered that the SSL/TLS plugins failed to validate the basic constraints extension in intermediate CA certificates CVE-2014-3695 Yves Younan and Richard Johnson discovered that emoticons with overly large le ...
A denial of service flaw was found in the way Pidgin's Mxit plug-in handled emoticons A malicious remote server or a man-in-the-middle attacker could potentially use this flaw to crash Pidgin by sending a specially crafted emoticon ...