[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2694Date: (C)2009-08-21   (M)2024-02-01


The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SUNALERT-266908
SECUNIA-36384
SECUNIA-36392
SECUNIA-36401
SECUNIA-36402
SECUNIA-36708
SECUNIA-37071
EXPLOIT-DB-9615
ADV-2009-2303
ADV-2009-2663
DSA-1870
RHSA-2009:1218
http://developer.pidgin.im/viewmtn/revision/info/6f7343166c673bf0496ecb1afec9b633c1d54a0e
http://developer.pidgin.im/wiki/ChangeLog
http://www.coresecurity.com/content/libpurple-arbitrary-write
http://www.pidgin.im/news/security/?id=34
https://bugzilla.redhat.com/show_bug.cgi?id=514957
oval:org.mitre.oval:def:10319
oval:org.mitre.oval:def:6320

CPE    22
cpe:/a:pidgin:pidgin:2.1.0
cpe:/a:pidgin:pidgin:2.1.1
cpe:/a:pidgin:pidgin:2.3.0
cpe:/a:pidgin:pidgin:2.3.1
...
CWE    1
CWE-399
OVAL    23
oval:org.secpod.oval:def:300610
oval:org.mitre.oval:def:6320
oval:org.secpod.oval:def:200611
oval:org.secpod.oval:def:100362
...

© SecPod Technologies