CVE-2007-4999
published 2007-10-29CVE-2007-4999: libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash)…
PriorityP411medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.81%
76.3th percentile
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.2.2-1 (bookworm) | pidgin 2.2.2-1 (bookworm) |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
| pidgin | pidgin | >= 0 < 2.2.2-1 | 2.2.2-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcj3-h9mr-5c65: libpurple in Pidgin 2
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-4999 [MEDIUM] CWE-20 GHSA-qcj3-h9mr-5c65: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
OSV
CVE-2007-4999: libpurple in Pidgin 2
osv·2007-10-29·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Ubuntu
Pidgin vulnerability
vendor_ubuntu·2007-11-28
CVE-2007-4999 Pidgin vulnerability
Title: Pidgin vulnerability
Summary: Pidgin vulnerability
It was discovered that Pidgin did not correctly handle certain logging
events. A remote attacker could send specially crafted messages and cause
the application to crash, leading to a denial of service.
Instructions: After a standard system upgrade you need to restart Pidgin to effect
the necessary changes.
Debian
CVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ...
vendor_debian·2007·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: pidgin - libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote ...
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Scope: local
bookworm: resolved (fixed in 2.2.2-1)
bullseye: resolved (fixed in 2.2.2-1)
forky: resolved (fixed in 2.2.2-1)
sid: resolved (fixed in 2.2.2-1)
trixie: resolved (fixed in 2.2.2-1)
Red Hat
CVE-2007-4999: libpurple in Pidgin 2
vendor_redhat·CVSS 4.3
CVE-2007-4999 [MEDIUM] CVE-2007-4999: libpurple in Pidgin 2
libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
Statement: Not vulnerable. This issue did not affect the versions of Pidgin or Gaim as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/38695http://secunia.com/advisories/27372http://secunia.com/advisories/27495http://secunia.com/advisories/27858http://www.pidgin.im/news/security/?id=24http://www.securityfocus.com/archive/1/483580/100/0/threadedhttp://www.securityfocus.com/bid/26205http://www.ubuntu.com/usn/usn-548-1http://www.vupen.com/english/advisories/2007/3624https://exchange.xforce.ibmcloud.com/vulnerabilities/38132https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18357https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00011.htmlhttp://osvdb.org/38695http://secunia.com/advisories/27372http://secunia.com/advisories/27495http://secunia.com/advisories/27858http://www.pidgin.im/news/security/?id=24http://www.securityfocus.com/archive/1/483580/100/0/threadedhttp://www.securityfocus.com/bid/26205http://www.ubuntu.com/usn/usn-548-1http://www.vupen.com/english/advisories/2007/3624https://exchange.xforce.ibmcloud.com/vulnerabilities/38132https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18357https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00011.html
2007-10-29
Published