Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3711

Опубликовано: 20 окт. 2010
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3pidginAffected
Red Hat Enterprise Linux 4pidginFixedRHSA-2010:078821.10.2010
Red Hat Enterprise Linux 5pidginFixedRHSA-2010:078821.10.2010
Red Hat Enterprise Linux 6pidginFixedRHSA-2010:089016.11.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=641921(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values

EPSS

Процентиль: 79%
0.01371
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

nvd
почти 15 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

debian
почти 15 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return ...

github
около 3 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

oracle-oval
больше 14 лет назад

ELSA-2010-0890: pidgin security update (MODERATE)

EPSS

Процентиль: 79%
0.01371
Низкий

5 Medium

CVSS2