Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23685
HistoryApr 10, 2020 - 12:33 a.m.

Arbitrary Code Execution

2020-04-1000:33:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.042

Percentile

92.3%

pidgin is vulnerable to arbitrary code execution. The vulnerability exists as a buffer overflow flaw was found in the way Pidgin initiates file transfers when using the Extensible Messaging and Presence Protocol (XMPP). If a Pidgin client initiates a file transfer, and the remote target sends a malformed response, it could cause Pidgin to crash or, potentially, execute arbitrary code with the permissions of the user running Pidgin. This flaw only affects accounts using XMPP, such as Jabber and Google Talk.

References