Lucene search

K
cve[email protected]CVE-2010-0013
HistoryJan 09, 2010 - 6:30 p.m.

CVE-2010-0013

2010-01-0918:30:01
CWE-22
web.nvd.nist.gov
37
cve
2010
0013
directory traversal
vulnerability
libpurple
pidgin
adium
msn protocol
remote attackers

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.072 Low

EPSS

Percentile

94.1%

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a … (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.

Affected configurations

NVD
Node
adiumadiumMatch1.3.8
OR
pidginpidginMatch2.6.4
Node
fedoraprojectfedoraMatch11
OR
fedoraprojectfedoraMatch12
Node
opensuseopensuseRange11.011.2
OR
suselinux_enterpriseMatch11.0-
OR
suselinux_enterprise_serverMatch10sp2-
OR
suselinux_enterprise_serverMatch10sp3-
Node
redhatenterprise_linuxMatch4.0
OR
redhatenterprise_linuxMatch5.0

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.072 Low

EPSS

Percentile

94.1%