Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6483

Опубликовано: 06 фев. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4

Описание

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

РелизСтатусПримечание
devel

released

1:2.10.9-0ubuntu1
lucid

ignored

end of life
precise

released

1:2.10.3-0ubuntu1.4
quantal

released

1:2.10.6-0ubuntu2.3
saucy

released

1:2.10.7-0ubuntu4.1.13.10.1
upstream

released

2.10.8

Показывать по

6.4 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

nvd
почти 12 лет назад

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

debian
почти 12 лет назад

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not ...

github
больше 3 лет назад

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

fstec
почти 12 лет назад

Уязвимость системы мгновенного обмена сообщениями Pidgin, позволяющая удаленному злоумышленнику вызвать отказ в обслуживании

6.4 Medium

CVSS2