CVE-2011-4922Sensitive Information Exposure in Pidgin

Severity
2.1LOWNVD
EPSS
0.1%
top 70.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 8
Latest updateMay 17

Description

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/pidgin< pidgin 2.7.11-1 (bookworm)
Debianpidgin/pidgin< 2.7.11-1+3
NVDpidgin/pidgin2.7.9+44

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g255-9j94-9w77: cipher2022-05-17
OSV
CVE-2011-4922: cipher2012-08-08

📋Vendor Advisories

3
Ubuntu
Pidgin vulnerabilities2012-07-09
Red Hat
Cipher API information disclosure in pidgin2011-02-10
Debian
CVE-2011-4922: pidgin - cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encrypti...2011

💬Community

1
Bugzilla
CVE-2011-4922 Cipher API information disclosure in pidgin2011-03-14