PT-2010-1839 · Adium+2 · Adium+3

Fabian Yamaguchi

+1

·

Published

2010-01-09

·

Updated

2024-01-26

·

CVE-2010-0013

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pidgin versions 2.6.4 Adium versions 1.3.8
Description A directory traversal issue in the MSN protocol plugin in libpurple allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon request. This issue is related to a problem where an emoticon download request is processed without a preceding text/x-mms-emoticon message announcing the emoticon's availability.
Recommendations For Pidgin version 2.6.4, consider disabling the MSN protocol plugin until a patch is available. For Adium version 1.3.8, restrict access to the MSN emoticon download feature to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2010-0013
OPENSUSE-SU-2024:10432-1
RHSA-2010:0044
RHSA-2010_0044

Affected Products

Adium
Pidgin
Red Hat
Libpurple