Lucene search

K
nessusTenable5032.PRM
HistoryAug 18, 2004 - 12:00 a.m.

Pidgin < 2.5.6 Multiple Buffer Overflow Vulnerabilities

2004-08-1800:00:00
Tenable
www.tenable.com
11

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.261

Percentile

96.8%

The remote host is running Pidgin earlier than 2.5.6. Such versions are reportedly affected by multiple remote buffer overflow vulnerabilities :

  • A buffer overflow issue in the β€˜decrypt_out()’ function can be exploited through specially crafted β€˜QQ’ packets. (CVE-2009-1374)

  • A buffer maintained by PurpleCircBuffer which is used by XMPP and Sametime protocol plugins can be corrupted if it’s exactly full and then more bytes are added to it. (CVE-2009-1375)

  • A buffer overflow is possible when initiating a file transfer to a malicious buddy over XMPP. (CVE-2009-1373)

  • An integer-overflow issue exists in the application due to a n incorrect typecasting of β€˜int64’ to β€˜size_t’. (CVE-2009-1376)

Successful exploitation could allow an attacker to execute arbitrary code on the remote host.

Binary data 5032.prm

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.261

Percentile

96.8%