Back

HIGH

pidgin: insufficient input validation in msn_slplink_process_msg()

Published Aug 20, 2009

Description

The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.

Affected products

Remediation

Red Hat mitigation

Users can lower the impact of this flaw by making sure their privacy settings only allow Pidgin to accept messages from the users on their buddy list. This will prevent exploitation of this flaw by other random MSN users.

Weaknesses (2)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 20, 2009
Updated Aug 7, 2024
Reserved Aug 5, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Aug 18, 2009
ENISA EUVD
Assigner mitre
Published Aug 20, 2009
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-2686