PT-2008-1078 · Pidgin+2 · Libpurple+3
Josh Bressers
·
Publicado
2008-07-07
·
Atualizado
2024-06-15
·
CVE-2008-2927
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libpurple versions prior to 2.4.3
Pidgin versions prior to 2.4.3
Adium versions prior to 1.3
Description
The issue is related to multiple integer overflows in the MSN protocol handler, specifically in the
msn slplink process msg functions. This can be exploited remotely, allowing attackers to execute arbitrary code via a malformed SLP message with a crafted offset value. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information.Recommendations
For libpurple versions prior to 2.4.3, update to version 2.4.3 or later.
For Pidgin versions prior to 2.4.3, update to version 2.4.3 or later.
For Adium versions prior to 1.3, update to version 1.3 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adium
Pidgin
Red Hat
Libpurple