Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4922

Опубликовано: 10 фев. 2011
Источник: redhat
CVSS2: 1.2
EPSS Низкий

Описание

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. A future update may address this issue in Red Hat Enterprise Linux 4 or 5 (it has been addressed in Red Hat Enterprise Linux 6). For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4pidginWill not fix
Red Hat Enterprise Linux 5pidginWill not fix
Red Hat Enterprise Linux 6pidginFixedRHSA-2011:061619.05.2011

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=684685Cipher API information disclosure in pidgin

EPSS

Процентиль: 30%
0.00108
Низкий

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.

nvd
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

debian
около 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retain ...

github
около 3 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.

oracle-oval
около 14 лет назад

ELSA-2011-0616: pidgin security and bug fix update (LOW)

EPSS

Процентиль: 30%
0.00108
Низкий

1.2 Low

CVSS2