PT-2009-1065 · Pidgin+2 · Libpurple+3
Published
2009-10-20
·
Updated
2017-09-19
·
CVE-2009-3615
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libpurple versions 2.6.3 and earlier
Pidgin versions prior to 2.6.3
Adium versions prior to 1.3.7
Description
The issue allows remote attackers to cause a denial of service, leading to a disruption in the availability of protected information. This can be achieved through crafted contact-list data for ICQ and possibly AIM. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations
For libpurple version 2.6.3, update to a version later than 2.6.3 to resolve the issue.
For Pidgin versions prior to 2.6.3, update to version 2.6.3 or later.
For Adium versions prior to 1.3.7, update to version 1.3.7 or later.
As a temporary workaround, consider restricting the use of the OSCAR protocol plugin in libpurple until a patch is available.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adium
Pidgin
Red Hat
Libpurple