ZeroHour

CVE-2016-2374

CVSS 3.0
8.1 high
EPSS
3%p87
Published
()
Modified
Description

An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.

Vendors
pidgincanonicaldebian
Products
pidgin, ubuntu linux, debian linux
Weakness
CWE-125, CWE-200
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news