CVE Vulnerabilities

CVE-2011-2943

Published: Aug 29, 2011 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4 LOW
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

Affected Software

Name Vendor Start Version End Version
Libpurple Pidgin 2.8.0 (including) 2.8.0 (including)
Libpurple Pidgin 2.9.0 (including) 2.9.0 (including)
Pidgin Pidgin * 2.9.0 (including)
Pidgin Pidgin 2.0.0 (including) 2.0.0 (including)
Pidgin Pidgin 2.0.1 (including) 2.0.1 (including)
Pidgin Pidgin 2.0.2 (including) 2.0.2 (including)
Pidgin Pidgin 2.1.0 (including) 2.1.0 (including)
Pidgin Pidgin 2.1.1 (including) 2.1.1 (including)
Pidgin Pidgin 2.2.0 (including) 2.2.0 (including)
Pidgin Pidgin 2.2.1 (including) 2.2.1 (including)
Pidgin Pidgin 2.2.2 (including) 2.2.2 (including)
Pidgin Pidgin 2.3.0 (including) 2.3.0 (including)
Pidgin Pidgin 2.3.1 (including) 2.3.1 (including)
Pidgin Pidgin 2.4.0 (including) 2.4.0 (including)
Pidgin Pidgin 2.4.1 (including) 2.4.1 (including)
Pidgin Pidgin 2.4.2 (including) 2.4.2 (including)
Pidgin Pidgin 2.4.3 (including) 2.4.3 (including)
Pidgin Pidgin 2.5.0 (including) 2.5.0 (including)
Pidgin Pidgin 2.5.1 (including) 2.5.1 (including)
Pidgin Pidgin 2.5.2 (including) 2.5.2 (including)
Pidgin Pidgin 2.5.3 (including) 2.5.3 (including)
Pidgin Pidgin 2.5.4 (including) 2.5.4 (including)
Pidgin Pidgin 2.5.5 (including) 2.5.5 (including)
Pidgin Pidgin 2.5.6 (including) 2.5.6 (including)
Pidgin Pidgin 2.5.7 (including) 2.5.7 (including)
Pidgin Pidgin 2.5.8 (including) 2.5.8 (including)
Pidgin Pidgin 2.5.9 (including) 2.5.9 (including)
Pidgin Pidgin 2.6.0 (including) 2.6.0 (including)
Pidgin Pidgin 2.6.1 (including) 2.6.1 (including)
Pidgin Pidgin 2.6.2 (including) 2.6.2 (including)
Pidgin Pidgin 2.6.4 (including) 2.6.4 (including)
Pidgin Pidgin 2.6.5 (including) 2.6.5 (including)
Pidgin Pidgin 2.6.6 (including) 2.6.6 (including)
Pidgin Pidgin 2.7.0 (including) 2.7.0 (including)
Pidgin Pidgin 2.7.1 (including) 2.7.1 (including)
Pidgin Pidgin 2.7.2 (including) 2.7.2 (including)
Pidgin Pidgin 2.7.3 (including) 2.7.3 (including)
Pidgin Pidgin 2.7.4 (including) 2.7.4 (including)
Pidgin Pidgin 2.7.5 (including) 2.7.5 (including)
Pidgin Pidgin 2.7.6 (including) 2.7.6 (including)
Pidgin Pidgin 2.7.7 (including) 2.7.7 (including)
Pidgin Pidgin 2.7.8 (including) 2.7.8 (including)
Pidgin Pidgin 2.7.9 (including) 2.7.9 (including)
Pidgin Pidgin 2.7.10 (including) 2.7.10 (including)
Pidgin Pidgin 2.7.11 (including) 2.7.11 (including)
Pidgin Pidgin 2.8.0 (including) 2.8.0 (including)
Pidgin Ubuntu hardy *
Pidgin Ubuntu upstream *

References