CVE-2009-1889
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers…
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- pidgin/pidgin
- Source
- secalert@redhat.com
References
- http://developer.pidgin.im/ticket/9483Patch, Vendor Advisory
- http://pidgin.im/pipermail/devel/2009-May/008227.htmlPatch
- http://secunia.com/advisories/35693
- http://secunia.com/advisories/35697
- http://secunia.com/advisories/35706
- http://secunia.com/advisories/37071
- http://www.redhat.com/support/errata/RHSA-2009-1139.html
- http://www.securityfocus.com/bid/35530
- http://www.ubuntu.com/usn/USN-796-1
- http://www.vupen.com/english/advisories/2009/1749
- https://bugzilla.redhat.com/show_bug.cgi?id=508738
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51448
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10004
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.html
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00176.html
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00228.html
- http://developer.pidgin.im/ticket/9483Patch, Vendor Advisory
- http://pidgin.im/pipermail/devel/2009-May/008227.htmlPatch
- http://secunia.com/advisories/35693
- http://secunia.com/advisories/35697
- http://secunia.com/advisories/35706
- http://secunia.com/advisories/37071
- http://www.redhat.com/support/errata/RHSA-2009-1139.html
- http://www.securityfocus.com/bid/35530
- http://www.ubuntu.com/usn/USN-796-1
- http://www.vupen.com/english/advisories/2009/1749
- https://bugzilla.redhat.com/show_bug.cgi?id=508738
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51448
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10004
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.