CVE-2016-2380 — Out-of-bounds Read in Pidgin
Severity
3.1LOWNVD
EPSS
0.5%
top 32.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 6
Latest updateMay 17
Description
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4
Affected Packages4 packages
Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3🕵️Threat Intelligence
2💬Community
1Bugzilla
▶