VulnerabilityModified
CVE-2016-2374
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin.
HIGH 8.1EPSS 3.23%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.23% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-200
- Affected
- pidgin/pidgin · canonical/ubuntu linux · debian/debian linux
- Source
- cret@cert.org
References
- http://www.debian.org/security/2016/dsa-3620Third Party Advisory
- http://www.pidgin.im/news/security/?id=107Patch, Vendor Advisory
- http://www.securityfocus.com/bid/91335Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0142/Technical Description, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3031-1Third Party Advisory
- https://security.gentoo.org/glsa/201701-38
- http://www.debian.org/security/2016/dsa-3620Third Party Advisory
- http://www.pidgin.im/news/security/?id=107Patch, Vendor Advisory
- http://www.securityfocus.com/bid/91335Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0142/Technical Description, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3031-1Third Party Advisory
- https://security.gentoo.org/glsa/201701-38
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.