Pidgin · Libpurple · CVE-2010-3711
**Name of the Vulnerable Software and Affected Versions**
Pidgin versions prior to 2.7.4
**Description**
The issue is related to the improper validation of the return value of the `purple base64 decode` function in libpurple, which can be exploited by remote authenticated users to cause a denial of service. This can result in a NULL pointer dereference and application crash via a crafted message. The problem is associated with plugins for MSN, MySpaceIM, XMPP, and Yahoo!, as well as the NTLM authentication support.
**Recommendations**
For versions prior to 2.7.4, update to version 2.7.4 or later to resolve the issue.