Resource management error in Pidgin - CVE-2012-2214
Published: July 3, 2012 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote #AU# to perform service disruption.
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
Affected software
pidgin (Alpine package)
How to mitigate CVE-2012-2214
pidgin (Alpine package) - update to 2.10.4-r0