Back

MEDIUM

pidgin: DoS via specially-crafted ICQWebMessage

Published Jul 1, 2009

Description

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 1, 2009
Updated Aug 7, 2024
Reserved Jun 2, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 28, 2009