CVE Vulnerabilities

CVE-2011-1091

Published: Mar 14, 2011 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Affected Software

Name Vendor Start Version End Version
Pidgin Pidgin 2.6.0 (including) 2.6.0 (including)
Pidgin Pidgin 2.6.1 (including) 2.6.1 (including)
Pidgin Pidgin 2.6.2 (including) 2.6.2 (including)
Pidgin Pidgin 2.6.4 (including) 2.6.4 (including)
Pidgin Pidgin 2.6.5 (including) 2.6.5 (including)
Pidgin Pidgin 2.6.6 (including) 2.6.6 (including)
Pidgin Pidgin 2.7.0 (including) 2.7.0 (including)
Pidgin Pidgin 2.7.1 (including) 2.7.1 (including)
Pidgin Pidgin 2.7.2 (including) 2.7.2 (including)
Pidgin Pidgin 2.7.3 (including) 2.7.3 (including)
Pidgin Pidgin 2.7.4 (including) 2.7.4 (including)
Pidgin Pidgin 2.7.5 (including) 2.7.5 (including)
Pidgin Pidgin 2.7.6 (including) 2.7.6 (including)
Pidgin Pidgin 2.7.7 (including) 2.7.7 (including)
Pidgin Pidgin 2.7.8 (including) 2.7.8 (including)
Pidgin Pidgin 2.7.9 (including) 2.7.9 (including)
Pidgin Pidgin 2.7.10 (including) 2.7.10 (including)

References