Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.901137
Category:Denial of Service
Title:Pidgin 'X-Status' Message Denial of Service Vulnerability - Windows
Summary:Pidgin is prone to a denial of service (DoS) vulnerability.
Description:Summary:
Pidgin is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
The flaw is caused by a NULL pointer dereference error when processing
malformed 'X-Status' messages, which could be exploited by attackers to
crash an affected application, creating a denial of service condition.

Vulnerability Impact:
Successful exploitation will allow remote attackers to cause the application
to crash, denying service to legitimate users.

Affected Software/OS:
Pidgin versions prior to 2.7.2

Solution:
Upgrade to Pidgin version 2.7.2 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-2528
40699
http://secunia.com/advisories/40699
41881
http://www.securityfocus.com/bid/41881
66506
http://www.osvdb.org/66506
ADV-2010-1887
http://www.vupen.com/english/advisories/2010/1887
ADV-2010-2221
http://www.vupen.com/english/advisories/2010/2221
SSA:2010-240-05
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462873
http://developer.pidgin.im/viewmtn/revision/diff/fcb70f7c12120206d30ad33223ff85be7b226d1c/with/8e8ff246492e45af8f8d0808296d6f2906794dc0/libpurple/protocols/oscar/family_icbm.c
http://developer.pidgin.im/viewmtn/revision/info/8e8ff246492e45af8f8d0808296d6f2906794dc0
http://www.pidgin.im/news/security/index.php?id=47
oval:org.mitre.oval:def:18359
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18359
pidgin-xstatus-dos(60566)
https://exchange.xforce.ibmcloud.com/vulnerabilities/60566
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.