Description
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages3 packages
🔴Vulnerability Details
4GHSAGHSA-qcj3-h9mr-5c65: libpurple in Pidgin 2↗2022-05-01 ▶ GHSAGHSA-r9v7-jgpj-m4mq: libpurple in Pidgin before 2↗2022-05-01 ▶ OSVCVE-2007-4999: libpurple in Pidgin 2↗2007-10-29 ▶ OSVCVE-2007-4996: libpurple in Pidgin before 2↗2007-10-01 ▶ 📋Vendor Advisories
4Red HatMSN nudges sent from unknown buddies can cause libpurple to crash↗2007-09-27 ▶ DebianCVE-2007-4996: pidgin - libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages fro...↗2007 ▶ DebianCVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ...↗2007 ▶ Red HatCVE-2007-4999: libpurple in Pidgin 2↗ ▶ 💬Community
1BugzillaCVE-2007-4996 MSN nudges sent from unknown buddies can cause libpurple to crash↗2007-10-01 ▶