Back

HIGH

pidgin/libpurple: MSN custom smiley request directory traversal file disclosure

Published Jan 9, 2010

Description

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 9, 2010
Updated Aug 7, 2024
Reserved Dec 14, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 27, 2009