PT-2008-1078 · Pidgin+2 · Libpurple+3
Josh Bressers
·
Published
2008-07-07
·
Updated
2024-06-15
·
CVE-2008-2927
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libpurple versions prior to 2.4.3
Pidgin versions prior to 2.4.3
Adium versions prior to 1.3
Description
The issue is related to multiple integer overflows in the MSN protocol handler, specifically in the
msn slplink process msg functions. This can be exploited remotely, allowing attackers to execute arbitrary code via a malformed SLP message with a crafted offset value. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information.Recommendations
For libpurple versions prior to 2.4.3, update to version 2.4.3 or later.
For Pidgin versions prior to 2.4.3, update to version 2.4.3 or later.
For Adium versions prior to 1.3, update to version 1.3 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adium
Pidgin
Red Hat
Libpurple