Pidgin DoS Vulnerability (CVE-2014-3696)
Release date:
Updated on:
Affected Systems:
Pidgin <2.10.10
Pidgin
Description:
Bugtraq id: 70705
CVE (CAN) ID: CVE-2014-3696
Pidgin is a multi-in-One world mainstream instant messaging software integration tool.
When Pidgin parses messages on the Groupwise server, the libpurple has a denial of service vulnerability because malicious servers or man-in-the-middle attackers specify to allocate a large amount of memory in many parts of the UI, attackers can exploit this vulnerability to cause the affected applications to crash.
<* Source: Richard Johnson
Yves Younan
*>
Suggestion:
Vendor patch:
Pidgin
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://pidgin.im/news/security? Id = 88
Http://hg.pidgin.im/pidgin/main/rev/2e4475087f04
This article permanently updates the link address: