CVE-2009-3084 — Improper Input Validation in Pidgin
Severity
5.0MEDIUMNVD
EPSS
1.4%
top 19.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 8
Latest updateMay 2
Description
The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9