5
CVSSv2

CVE-2014-3698

Published: 29/10/2014 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin prior to 2.10.10 allows remote malicious users to obtain sensitive information from process memory via a crafted XMPP message.

Vulnerable Product Search on Vulmon Subscribe to Product

pidgin pidgin

pidgin pidgin 2.10.8

pidgin pidgin 2.10.7

pidgin pidgin 2.10.0

pidgin pidgin 2.10.2

pidgin pidgin 2.10.1

pidgin pidgin 2.10.6

pidgin pidgin 2.10.5

pidgin pidgin 2.10.4

pidgin pidgin 2.10.3

Vendor Advisories

Synopsis Moderate: pidgin security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for pidgin is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Several security issues were fixed in Pidgin ...
Multiple vulnerabilities have been discovered in Pidgin, a multi-protocol instant messaging client: CVE-2014-3694 It was discovered that the SSL/TLS plugins failed to validate the basic constraints extension in intermediate CA certificates CVE-2014-3695 Yves Younan and Richard Johnson discovered that emoticons with overly large le ...
An information disclosure flaw was discovered in the way Pidgin parsed XMPP messages A malicious remote server or a man-in-the-middle attacker could potentially use this flaw to disclose a portion of memory belonging to the Pidgin process by sending a specially crafted XMPP message ...