CVE-2008-2957
published 2008-07-01CVE-2008-2957: The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of…
PriorityP426medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
2.10%
79.6th percentile
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.4.3-4 (bookworm) | pidgin 2.4.3-4 (bookworm) |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.4.3-4 | 2.4.3-4 |
| pidgin | pidgin | >= 0 < 2.4.3-4 | 2.4.3-4 |
| pidgin | pidgin | >= 0 < 2.4.3-4 | 2.4.3-4 |
| pidgin | pidgin | >= 0 < 2.4.3-4 | 2.4.3-4 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2008-11-24·CVSS 6.8
CVE-2008-2927 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
It was discovered that Pidgin did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a specially
crafted message and possibly execute arbitrary code with user privileges.
(CVE-2008-2927)
It was discovered that Pidgin did not properly handle file transfers containing
a long filename and special characters in the MSN protocol handler. A remote
attacker could send a specially crafted filename in a file transfer request
and cause Pidgin to crash, leading to a denial of service. (CVE-2008-2955)
It was discovered that Pidgin did not impose resource limitations in the UPnP
service. A remote attacker could cause Pidgin to download arbitrary files
and cause a denial of service fro
Debian
CVE-2008-2957: pidgin - The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remo...
vendor_debian·2008·CVSS 6.4
CVE-2008-2957 [MEDIUM] CVE-2008-2957: pidgin - The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remo...
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
Scope: local
bookworm: resolved (fixed in 2.4.3-4)
bullseye: resolved (fixed in 2.4.3-4)
forky: resolved (fixed in 2.4.3-4)
sid: resolved (fixed in 2.4.3-4)
trixie: resolved (fixed in 2.4.3-4)
Red Hat
pidgin: unrestricted download of arbitrary files triggered via UPnP
vendor_redhat·2007-05-11·CVSS 6.4
CVE-2008-2957 [MEDIUM] pidgin: unrestricted download of arbitrary files triggered via UPnP
pidgin: unrestricted download of arbitrary files triggered via UPnP
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
GHSA
GHSA-6pwc-353h-qw4p: The UPnP functionality in Pidgin 2
ghsa_unreviewed·2022-05-01
CVE-2008-2957 [MEDIUM] CWE-20 GHSA-6pwc-353h-qw4p: The UPnP functionality in Pidgin 2
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
OSV
CVE-2008-2957: The UPnP functionality in Pidgin 2
osv·2008-07-01·CVSS 6.4
CVE-2008-2957 [MEDIUM] CVE-2008-2957: The UPnP functionality in Pidgin 2
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
No detection rules found.
No public exploits indexed.
http://crisp.cs.du.edu/?q=ca2007-1http://secunia.com/advisories/32859http://secunia.com/advisories/33102http://support.avaya.com/elmodocs2/security/ASA-2008-493.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:025http://www.openwall.com/lists/oss-security/2008/06/27/3http://www.redhat.com/support/errata/RHSA-2008-1023.htmlhttp://www.securityfocus.com/bid/29985http://www.ubuntu.com/usn/USN-675-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17599https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9076http://crisp.cs.du.edu/?q=ca2007-1http://secunia.com/advisories/32859http://secunia.com/advisories/33102http://support.avaya.com/elmodocs2/security/ASA-2008-493.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:025http://www.openwall.com/lists/oss-security/2008/06/27/3http://www.redhat.com/support/errata/RHSA-2008-1023.htmlhttp://www.securityfocus.com/bid/29985http://www.ubuntu.com/usn/USN-675-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17599https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9076
2008-07-01
Published