CVE Vulnerabilities

CVE-2008-2927

Published: Jul 07, 2008 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

Affected Software

Name Vendor Start Version End Version
Pidgin Pidgin * 2.4.2 (including)
Pidgin Pidgin 2.0.0 (including) 2.0.0 (including)
Pidgin Pidgin 2.0.1 (including) 2.0.1 (including)
Pidgin Pidgin 2.0.2 (including) 2.0.2 (including)
Pidgin Pidgin 2.1.0 (including) 2.1.0 (including)
Pidgin Pidgin 2.1.1 (including) 2.1.1 (including)
Pidgin Pidgin 2.2.0 (including) 2.2.0 (including)
Pidgin Pidgin 2.2.1 (including) 2.2.1 (including)
Pidgin Pidgin 2.2.2 (including) 2.2.2 (including)
Pidgin Pidgin 2.3.0 (including) 2.3.0 (including)
Pidgin Pidgin 2.3.1 (including) 2.3.1 (including)
Pidgin Pidgin 2.4.0 (including) 2.4.0 (including)
Pidgin Pidgin 2.4.1 (including) 2.4.1 (including)

References