CVE-2011-4939NULL Pointer Dereference in Pidgin

Severity
6.4MEDIUMNVD
EPSS
1.1%
top 21.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateMay 14

Description

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

debiandebian/pidgin< pidgin 2.10.2-1 (bookworm)
Debianpidgin/pidgin< 2.10.2-1+3
NVDpidgin/pidgin2.10.1+45

🔴Vulnerability Details

2
GHSA
GHSA-fqpj-4v5c-wf35: The pidgin_conv_chat_rename_user function in gtkconv2022-05-14
OSV
CVE-2011-4939: The pidgin_conv_chat_rename_user function in gtkconv2012-03-15

📋Vendor Advisories

3
Ubuntu
Pidgin vulnerabilities2012-07-09
Red Hat
pidgin: NULL pointer dereference in the XMPP protocol plug-in by renaming user name2011-07-08
Debian
CVE-2011-4939: pidgin - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 a...2011

💬Community

1
Bugzilla
CVE-2011-4939 pidgin: NULL pointer dereference in the XMPP protocol plug-in by renaming user name2012-03-14