CVE-2007-4996
published 2007-10-01CVE-2007-4996: libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.76%
75.6th percentile
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.2.1-1 (bookworm) | pidgin 2.2.1-1 (bookworm) |
| debian | pidgin | < pidgin 2.2.2-1 (bookworm) | pidgin 2.2.2-1 (bookworm) |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.2.1-1 | 2.2.1-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.1-1 | 2.2.1-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.1-1 | 2.2.1-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.1-1 | 2.2.1-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcj3-h9mr-5c65: libpurple in Pidgin 2
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-4999 [MEDIUM] CWE-20 GHSA-qcj3-h9mr-5c65: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
GHSA
GHSA-r9v7-jgpj-m4mq: libpurple in Pidgin before 2
ghsa_unreviewed·2022-05-01
CVE-2007-4996 [MEDIUM] GHSA-r9v7-jgpj-m4mq: libpurple in Pidgin before 2
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
OSV
CVE-2007-4999: libpurple in Pidgin 2
osv·2007-10-29·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
OSV
CVE-2007-4996: libpurple in Pidgin before 2
osv·2007-10-01·CVSS 4.3
CVE-2007-4996 [MEDIUM] CVE-2007-4996: libpurple in Pidgin before 2
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
Red Hat
MSN nudges sent from unknown buddies can cause libpurple to crash
vendor_redhat·2007-09-27·CVSS 4.3
CVE-2007-4996 [MEDIUM] MSN nudges sent from unknown buddies can cause libpurple to crash
MSN nudges sent from unknown buddies can cause libpurple to crash
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
Statement: Not vulnerable. These issues did not affect the versions of Pidgin or Gaim as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Debian
CVE-2007-4996: pidgin - libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages fro...
vendor_debian·2007·CVSS 4.3
CVE-2007-4996 [MEDIUM] CVE-2007-4996: pidgin - libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages fro...
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
Scope: local
bookworm: resolved (fixed in 2.2.1-1)
bullseye: resolved (fixed in 2.2.1-1)
forky: resolved (fixed in 2.2.1-1)
sid: resolved (fixed in 2.2.1-1)
trixie: resolved (fixed in 2.2.1-1)
Debian
CVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ...
vendor_debian·2007·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ...
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
Red Hat
CVE-2007-4999: libpurple in Pidgin 2
vendor_redhat·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Statement: Not vulnerable. This issue did not affect the versions of Pidgin or Gaim as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
No detection rules found.
No public exploits indexed.
http://fedoranews.org/updates/FEDORA-2007-236.shtmlhttp://secunia.com/advisories/27010http://secunia.com/advisories/27088http://www.pidgin.im/news/security/?id=23http://www.securityfocus.com/archive/1/481402/100/0/threadedhttp://www.securityfocus.com/bid/25872http://www.vupen.com/english/advisories/2007/3321https://exchange.xforce.ibmcloud.com/vulnerabilities/36884https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18261http://fedoranews.org/updates/FEDORA-2007-236.shtmlhttp://secunia.com/advisories/27010http://secunia.com/advisories/27088http://www.pidgin.im/news/security/?id=23http://www.securityfocus.com/archive/1/481402/100/0/threadedhttp://www.securityfocus.com/bid/25872http://www.vupen.com/english/advisories/2007/3321https://exchange.xforce.ibmcloud.com/vulnerabilities/36884https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18261
2007-10-01
Published