CVE-2009-1376
Published May 26, 2009
Last updated a year ago
Overview
- Description
- Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-189
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FC23273-E322-40E0-AD26-2F272EB5E7A1", "versionEndIncluding": "2.5.5" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.4.0:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7D1DFC7-4B7F-4006-9058-8335A292821E" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.4.1:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "12095F49-8DFD-4C74-9454-5C3A5992A3FE" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.4.2:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C62110B5-61D7-406D-B1A5-65AEC202DDFF" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.4.3:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD01B8C6-7D3E-4FF9-A5B5-AAF33F4CEBB1" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.5.0:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD6D98DC-06FC-46E7-A790-98A0B43A4E8B" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.5.2:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FEE4F73-A426-4B47-8BAF-1C7D2F955850" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.5.3:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "777EF35C-195A-4784-986D-3811CF1DCF16" }, { "criteria": "cpe:2.3:a:pidgin:pidgin:2.5.4:32_bit:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2DD21F1-7A08-4F2D-B8EA-C02771E960FE" } ], "operator": "OR" } ] } ]