PT-2009-1018 · Pidgin+1 · Libpurple+1

Federico Muttis

·

Published

2009-08-18

·

Updated

2017-09-19

·

CVE-2009-2694

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libpurple versions 2.5.9 and earlier
Description The issue is related to the msn slplink process msg function in libpurple, which allows remote attackers to execute arbitrary code or cause a denial of service by sending multiple crafted SLP messages. This can lead to memory corruption and application crash, compromising the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For libpurple versions 2.5.9 and earlier, consider updating to a version later than 2.5.9 to resolve the issue. As a temporary workaround, restrict the use of the msn slplink process msg function until a patch is available. Additionally, be cautious when receiving SLP messages to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02899
BDU:2015-07364
BDU:2015-07366
BDU:2015-07368
CVE-2009-2694
DSA-1870-1
OPENSUSE-SU-2024:10432-1
RHSA-2009:1218
RHSA-2009_1218

Affected Products

Red Hat
Libpurple