9.8
CVSSv3

CVE-2017-5668

Published: 14/03/2017 Updated: 16/03/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

bitlbee-libpurple prior to 3.5.1 allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.

Vulnerable Product Search on Vulmon Subscribe to Product

bitlbee bitlbee

bitlbee bitlbee-libpurple

Vendor Advisories

Receiving a file transfer request from a contact not in the contact list results in a null pointer dereference, leading to remote DoS by malicious remote clients Additionally, due to an incomplete fix of the issue above in BitlBee 35, the bitlbee-libpurple variant is still affected in 35 ...