Pidgin 2.13.0 Denial of Service via Malformed Username
Published Mar 21, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.19%
Description
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.
Affected products
-
- Version 2.13.0StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 6
pidgin
Out of support scope
Red Hat Enterprise Linux 7
pidgin
Fix deferred
Red Hat Enterprise Linux 8
pidgin
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | pidgin | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | pidgin | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | pidgin | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact denial of service flaw in Pidgin allows a local attacker to crash the application. By providing an excessively long username string during account creation, the application becomes unavailable when attempting to join a chat.
Red Hat mitigation
Red Hat is not aware of a practical temporary workaround that fully or partially mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-25544 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2449948 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-25544
- https://pidgin.im/ product
- https://www.cve.org/CVERecord?id=CVE-2019-25544
- https://www.exploit-db.com/exploits/46930 exploitVDB Entry
- https://www.vulncheck.com/advisories/pidgin-denial-of-service-via-malformed-username third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-25544 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2449948 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-25544 | ||
| https://pidgin.im/ | product | |
| https://www.cve.org/CVERecord?id=CVE-2019-25544 | ||
| https://www.exploit-db.com/exploits/46930 | exploitVDB Entry | |
| https://www.vulncheck.com/advisories/pidgin-denial-of-service-via-malformed-username | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.