cbcvebase.
CVE-2016-2367
published 2017-01-06

CVE-2016-2367: An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an…

PriorityP427medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.95%
78.0th percentile
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianpidgin< pidgin 2.11.0-1 (bookworm)pidgin 2.11.0-1 (bookworm)
pidginpidgin<= 2.10.12
pidginpidgin
pidginpidgin>= 0 < 2.11.0-12.11.0-1
pidginpidgin>= 0 < 2.11.0-12.11.0-1
pidginpidgin>= 0 < 2.11.0-12.11.0-1
pidginpidgin>= 0 < 2.11.0-12.11.0-1

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.