Summary
The host is installed with Pidgin and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote attackers to conduct denial of service or execute arbitrary programs or spoof iq traffic.
Impact Level: System/Application
Solution
Upgrade to Pidgin version 2.10.8 or later,
For updates refer to http://www.pidgin.im/
Insight
The flaws are due to an,
- Improper validation of data by the Yahoo protocol plugin.
- Improper validation of argument counts by IRC protocol plugin.
- Improper validation of input to content-length header.
- Integer signedness error in the 'MXit' functionality.
- Integer overflow in 'ibpurple/protocols/gg/lib/http.c' in the 'Gadu-Gadu' (gg) parser.
- Error due to incomplete fix for earlier flaw.
- Integer overflow condition in the 'process_chunked_data' function in 'util.c'.
- Error in 'STUN' protocol implementation in 'libpurple'.
- Error in the 'XMPP' protocol plugin in 'libpurple'.
- Error in the MSN module.
- Improper validation of the length field in 'libpurple/protocols/yahoo/libymsg.c'.
- Improper allocation of memory by 'util.c' in 'libpurple'.
- Error in the libx11 library.
- Multiple integer signedness errors in libpurple.
Affected
Pidgin version before 2.10.8.
Detection
Get the installed version with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat and Reader Multiple Vulnerabilities -Oct10 (Windows)
- Adobe Acrobat and Reader Multiple Vulnerabilities -July10 (Windows)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 Feb13 (Windows)
- Adobe Flash Player 'SWF' File Multiple Code Execution Vulnerability - Windows
- Adobe Air Multiple Vulnerabilities -01 May 13 (Windows)