PT-2010-3291 · Pidgin+1 · Pidgin+1

CVE-2010-1624

·

Published

2010-05-14

·

Updated

2023-03-31

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Pidgin versions prior to 2.7.0
Description The issue allows remote authenticated users to cause a denial of service, resulting in a NULL pointer dereference and application crash. This is achieved by sending a custom emoticon in a malformed SLP message.
Recommendations For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue. As a temporary workaround, consider disabling the use of custom emoticons in SLP messages until a patch is available. Restrict access to the MSN protocol plugin to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1624
OPENSUSE-SU-2024:10432-1
RHSA-2010:0788
RHSA-2010_0788

Affected Products

Pidgin
Red Hat