VulnerabilityModified
CVE-2007-4996
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an…
MEDIUM 4.3EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- pidgin/pidgin
- Source
- secalert@redhat.com
References
- http://fedoranews.org/updates/FEDORA-2007-236.shtml
- http://secunia.com/advisories/27010Patch, Vendor Advisory
- http://secunia.com/advisories/27088
- http://www.pidgin.im/news/security/?id=23Patch
- http://www.securityfocus.com/archive/1/481402/100/0/threaded
- http://www.securityfocus.com/bid/25872
- http://www.vupen.com/english/advisories/2007/3321
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36884
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18261
- http://fedoranews.org/updates/FEDORA-2007-236.shtml
- http://secunia.com/advisories/27010Patch, Vendor Advisory
- http://secunia.com/advisories/27088
- http://www.pidgin.im/news/security/?id=23Patch
- http://www.securityfocus.com/archive/1/481402/100/0/threaded
- http://www.securityfocus.com/bid/25872
- http://www.vupen.com/english/advisories/2007/3321
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36884
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18261
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.