Input validation error in Pidgin - CVE-2013-0273

 

Input validation error in Pidgin - CVE-2013-0273

Published: February 16, 2013 / Updated: August 4, 2020


Vulnerability identifier: #VU33911
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0273
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.


Affected software

Pidgin
Gentoo Linux
Slackware Linux
pidgin (Alpine package)

How to mitigate CVE-2013-0273

Install update from vendor's website.

Pidgin - update to 2.10.7
pidgin (Alpine package) - update to 2.10.7-r0

External References

Related Security Bulletins