ZeroHour

CVE-2016-2380

CVSS 3.0
3.1 low
EPSS
2%p77
Published
()
Modified
Description

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.

Vendors
pidgincanonicaldebian
Products
pidgin, ubuntu linux, debian linux
Weakness
CWE-125, CWE-200
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news