SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1889

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers…

MEDIUM 5.0EPSS 3.38%

Does this matter?

Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.

Description

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
3.38% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-399
Affected
pidgin/pidgin
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.