CVE-2008-2957Improper Input Validation in Pidgin

Severity
6.4MEDIUMNVD
EPSS
1.7%
top 17.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 1
Latest updateMay 1

Description

The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

debiandebian/pidgin< pidgin 2.4.3-4 (bookworm)
Debianpidgin/pidgin< 2.4.3-4+3
NVDpidgin/pidgin2.0.0

🔴Vulnerability Details

2
GHSA
GHSA-6pwc-353h-qw4p: The UPnP functionality in Pidgin 22022-05-01
OSV
CVE-2008-2957: The UPnP functionality in Pidgin 22008-07-01

📋Vendor Advisories

3
Ubuntu
Pidgin vulnerabilities2008-11-24
Debian
CVE-2008-2957: pidgin - The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remo...2008
Red Hat
pidgin: unrestricted download of arbitrary files triggered via UPnP2007-05-11

💬Community

1
Bugzilla
CVE-2008-2957 pidgin: unrestricted download of arbitrary files triggered via UPnP2008-07-02