Back

MEDIUM

pidgin: Possible spoofing using iq replies in XMPP protocol plugin

Published Feb 6, 2014

Description

The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 6, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 28, 2014