Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mwr-c2hc-vr2x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

EPSS

Процентиль: 79%
0.01217
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-125
CWE-200

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

CVSS3: 4.2
redhat
больше 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

CVSS3: 5.9
nvd
около 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

CVSS3: 5.9
debian
около 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pid ...

suse-cvrf
больше 9 лет назад

Security update for pidgin

EPSS

Процентиль: 79%
0.01217
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-125
CWE-200