9.3

CVE-2009-1376

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows.  NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.

Data is provided by the National Vulnerability Database (NVD)
PidginPidgin Version <= 2.5.5
PidginPidgin Version2.4.0 Update32_bit
PidginPidgin Version2.4.1 Update32_bit
PidginPidgin Version2.4.2 Update32_bit
PidginPidgin Version2.4.3 Update32_bit
PidginPidgin Version2.5.0 Update32_bit
PidginPidgin Version2.5.2 Update32_bit
PidginPidgin Version2.5.3 Update32_bit
PidginPidgin Version2.5.4 Update32_bit
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 25.89% 0.96
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C