Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1000030

Опубликовано: 05 сент. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*
Версия до 2.11.0 (исключая)

EPSS

Процентиль: 73%
0.00778
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

redhat
больше 9 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

CVSS3: 9.8
debian
больше 7 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates ...

CVSS3: 9.8
github
больше 3 лет назад

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

EPSS

Процентиль: 73%
0.00778
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-295