Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1000030

Опубликовано: 05 сент. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*
Версия до 2.11.0 (исключая)

EPSS

Процентиль: 77%
0.01844
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

redhat
около 10 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

CVSS3: 9.8
debian
почти 8 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates ...

CVSS3: 9.8
github
больше 4 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

EPSS

Процентиль: 77%
0.01844
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295