Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g255-9j94-9w77

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

EPSS

Процентиль: 30%
0.00108
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.

redhat
больше 14 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

nvd
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

debian
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retain ...

oracle-oval
около 14 лет назад

ELSA-2011-0616: pidgin security and bug fix update (LOW)

EPSS

Процентиль: 30%
0.00108
Низкий

Дефекты

CWE-200