Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-2943

Опубликовано: 20 июл. 2011
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

Отчет

Not vulnerable. This issue did not affect the versions of pidgin as shipped with Red Hat Enterprise Linux 4, 5, or 6 as they contained a version of pidgin that did not support /who IRC protocol command.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4pidginNot affected
Red Hat Enterprise Linux 5pidginNot affected
Red Hat Enterprise Linux 6pidginNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=722939pidgin: Crash in IRC protocol plug-in by listing set of users (/who command) upon session startup

EPSS

Процентиль: 88%
0.03955
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

nvd
больше 14 лет назад

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

debian
больше 14 лет назад

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpu ...

github
больше 3 лет назад

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

EPSS

Процентиль: 88%
0.03955
Низкий

4 Medium

CVSS2