Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-2367

Опубликовано: 06 янв. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 3.5
CVSS3: 5.9

Описание

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

РелизСтатусПримечание
devel

released

1:2.10.12-0ubuntu6
esm-apps-legacy/xenial

released

1:2.10.12-0ubuntu5.1
esm-apps/xenial

released

1:2.10.12-0ubuntu5.1
esm-infra-legacy/trusty

released

1:2.10.9-0ubuntu3.3
precise

released

1:2.10.3-0ubuntu1.7
trusty

released

1:2.10.9-0ubuntu3.3
trusty/esm

released

1:2.10.9-0ubuntu3.3
upstream

released

2.11.0-1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

3.5 Low

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
около 10 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

CVSS3: 5.9
nvd
больше 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

CVSS3: 5.9
debian
больше 9 лет назад

An information leak exists in the handling of the MXIT protocol in Pid ...

CVSS3: 5.9
github
больше 4 лет назад

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

suse-cvrf
почти 10 лет назад

Security update for pidgin

3.5 Low

CVSS2

5.9 Medium

CVSS3