Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25544

Опубликовано: 21 мар. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

A flaw was found in Pidgin. Local attackers can exploit this denial of service vulnerability by providing an excessively long username string during account creation. This can cause the application to crash when joining a chat, leading to the application becoming unavailable.

Отчет

This Moderate impact denial of service flaw in Pidgin allows a local attacker to crash the application. By providing an excessively long username string during account creation, the application becomes unavailable when attempting to join a chat.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully or partially mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pidginOut of support scope
Red Hat Enterprise Linux 7pidginFix deferred
Red Hat Enterprise Linux 8pidginFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2449948Pidgin: Pidgin: Denial of Service via excessively long username

EPSS

Процентиль: 9%
0.00187
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
5 месяцев назад

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

CVSS3: 6.2
nvd
5 месяцев назад

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

CVSS3: 6.2
debian
5 месяцев назад

Pidgin 2.13.0 contains a denial of service vulnerability that allows l ...

suse-cvrf
около 2 месяцев назад

Security update for libgnt, meson, pidgin

CVSS3: 6.2
github
5 месяцев назад

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

EPSS

Процентиль: 9%
0.00187
Низкий

6.2 Medium

CVSS3