CVE-2009-1373Improper Restriction of Operations within the Bounds of a Memory Buffer in Pidgin

Severity
7.1HIGHNVD
EPSS
8.4%
top 7.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateMay 2

Description

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

debiandebian/pidgin< pidgin 2.5.6-1 (bookworm)
Debianpidgin/pidgin< 2.5.6-1+3
NVDpidgin/pidgin2.5.5+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hfwm-9244-px83: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 22022-05-02
OSV
CVE-2009-1373: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 22009-05-26

📋Vendor Advisories

4
Ubuntu
Pidgin vulnerabilities2009-06-03
Ubuntu
Gaim vulnerabilities2009-06-03
Red Hat
pidgin file transfer buffer overflow2009-05-02
Debian
CVE-2009-1373: pidgin - Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) b...2009

💬Community

2
Bugzilla
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities2009-05-26
Bugzilla
CVE-2009-1373 pidgin file transfer buffer overflow2009-05-12