Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-0013Path Traversal in Adium

CWE-22Path Traversal14 documents9 sources
Severity
7.5HIGHNVD
CNA5.0OSV5.0
EPSS
12.8%
top 5.94%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 9
Latest updateMay 2

Description

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emo

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Debianpidgin/pidgin< 2.6.5-1+3
NVDadium/adium1.3.8
NVDpidgin/pidgin2.6.4
NVDopensuse/opensuse11.011.2

Also affects: Fedora 11, 12, Linux Enterprise 11.0, Enterprise Linux 4.0, 5.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v6ph-x2c7-6g37: Directory traversal vulnerability in slp2022-05-02
OSV
CVE-2010-0013: Directory traversal vulnerability in slp2010-01-09
CVEList
CVE-2010-0013: Directory traversal vulnerability in slp2010-01-09

💥Exploits & PoCs

1
Exploit-DB
Pidgin MSN 2.6.4 - File Download2010-01-19

📋Vendor Advisories

4
Ubuntu
Pidgin vulnerabilities2010-01-18
Debian
CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...2010
Red Hat
pidgin/libpurple: MSN custom smiley request directory traversal file disclosure2009-12-27
Red Hat
pidgin MSN protocol plugin memory corruption2009-12-27

💬Community

3
Bugzilla
CVE-2011-0013 CVE-2010-3718 tomcat5 various flaws [fedora-all]2011-02-07
Bugzilla
CVE-2010-0277 pidgin MSN protocol plugin memory corruption2010-01-11
Bugzilla
CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure2010-01-05
CVE-2010-0013 — Path Traversal in Adium | cvebase