Lucene search

K
freebsdFreeBSDAA71DAAA-9F8C-11E1-BD0A-0082A0C18826
HistoryMay 16, 2012 - 12:00 a.m.

pidgin-otr -- format string vulnerability

2012-05-1600:00:00
vuxml.freebsd.org
23

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.055

Percentile

93.2%

The authors report:

Versions 3.2.0 and earlier of the pidgin-otr plugin contain
a format string security flaw. This flaw could potentially be
exploited by a remote attacker to cause arbitrary code to be
executed on the user’s machine.
The flaw is in pidgin-otr, not in libotr. Other applications
that use libotr are not affected.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchpidgin-otr< 3.2.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.055

Percentile

93.2%