Lucene search

K
nvd[email protected]NVD:CVE-2011-4602
HistoryDec 17, 2011 - 3:54 a.m.

CVE-2011-4602

2011-12-1703:54:45
CWE-20
web.nvd.nist.gov
8

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.028

Percentile

90.6%

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.

Affected configurations

Nvd
Node
pidginpidginRange2.10.0
OR
pidginpidginMatch2.0.0
OR
pidginpidginMatch2.0.1
OR
pidginpidginMatch2.0.2
OR
pidginpidginMatch2.1.0
OR
pidginpidginMatch2.1.1
OR
pidginpidginMatch2.2.0
OR
pidginpidginMatch2.2.1
OR
pidginpidginMatch2.2.2
OR
pidginpidginMatch2.3.0
OR
pidginpidginMatch2.3.1
OR
pidginpidginMatch2.4.0
OR
pidginpidginMatch2.4.1
OR
pidginpidginMatch2.4.2
OR
pidginpidginMatch2.4.3
OR
pidginpidginMatch2.5.0
OR
pidginpidginMatch2.5.1
OR
pidginpidginMatch2.5.2
OR
pidginpidginMatch2.5.3
OR
pidginpidginMatch2.5.4
OR
pidginpidginMatch2.5.5
OR
pidginpidginMatch2.5.6
OR
pidginpidginMatch2.5.7
OR
pidginpidginMatch2.5.8
OR
pidginpidginMatch2.5.9
OR
pidginpidginMatch2.6.0
OR
pidginpidginMatch2.6.1
OR
pidginpidginMatch2.6.2
OR
pidginpidginMatch2.6.3
OR
pidginpidginMatch2.6.4
OR
pidginpidginMatch2.6.5
OR
pidginpidginMatch2.6.6
OR
pidginpidginMatch2.7.1
OR
pidginpidginMatch2.7.2
OR
pidginpidginMatch2.7.3
OR
pidginpidginMatch2.7.4
OR
pidginpidginMatch2.7.5
OR
pidginpidginMatch2.7.6
OR
pidginpidginMatch2.7.7
OR
pidginpidginMatch2.7.8
OR
pidginpidginMatch2.7.9
OR
pidginpidginMatch2.7.10
OR
pidginpidginMatch2.7.11
OR
pidginpidginMatch2.8.0
OR
pidginpidginMatch2.9.0
VendorProductVersionCPE
pidginpidgin*cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*
pidginpidgin2.0.0cpe:2.3:a:pidgin:pidgin:2.0.0:*:*:*:*:*:*:*
pidginpidgin2.0.1cpe:2.3:a:pidgin:pidgin:2.0.1:*:*:*:*:*:*:*
pidginpidgin2.0.2cpe:2.3:a:pidgin:pidgin:2.0.2:*:*:*:*:*:*:*
pidginpidgin2.1.0cpe:2.3:a:pidgin:pidgin:2.1.0:*:*:*:*:*:*:*
pidginpidgin2.1.1cpe:2.3:a:pidgin:pidgin:2.1.1:*:*:*:*:*:*:*
pidginpidgin2.2.0cpe:2.3:a:pidgin:pidgin:2.2.0:*:*:*:*:*:*:*
pidginpidgin2.2.1cpe:2.3:a:pidgin:pidgin:2.2.1:*:*:*:*:*:*:*
pidginpidgin2.2.2cpe:2.3:a:pidgin:pidgin:2.2.2:*:*:*:*:*:*:*
pidginpidgin2.3.0cpe:2.3:a:pidgin:pidgin:2.3.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 451

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

High

EPSS

0.028

Percentile

90.6%