Home→Descriptions→SA49831
| Secunia ID | |
| CVE-ID | |
| Release Date |
06 Jul 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Pidgin 2.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Pidgin, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error within the "mxit_show_message()" function (libpurple/protocols/mxit/markup.c) when parsing incoming messages containing inline images. This can be exploited to cause a stack-based buffer overflow via a specially crafted RX message. Successful exploitation of the vulnerability may allow execution of arbitrary code. The vulnerability is reported in versions prior to 2.10.5. |
| Solution |
Update to version 2.10.5. |
| Reported by |
The vendor credits Ulf Härnhammar. |
| Original Advisory |