CVE Vulnerabilities

CVE-2015-8833

Published: Apr 12, 2016 | Modified: Aug 04, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the Authenticate buddy menu item.

Affected Software

Name Vendor Start Version End Version
Pidgin-otr Cypherpunks * 4.0.1 (including)
Pidgin-otr Ubuntu precise *
Pidgin-otr Ubuntu trusty *
Pidgin-otr Ubuntu upstream *
Pidgin-otr Ubuntu wily *

References