← Back

CVE-2009-3084

nvd nist
Published: Sep 8, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.

Affected (38)

Products: Pidgin: Pidgin, Libpurple
2 products
Pidgin
Libpurple
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Pidgin
Up to 2.6.1
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0.2
Version 2.1.0
Version 2.1.1
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.3.0
Version 2.3.1
Version 2.4.0
Version 2.4.0 32_bit
Version 2.4.1
Version 2.4.1 32_bit
Version 2.4.2
Version 2.4.2 32_bit
Version 2.4.3
Version 2.4.3 32_bit
Version 2.5.0
Version 2.5.0 32_bit
Version 2.5.1
Version 2.5.2
Version 2.5.2 32_bit
Version 2.5.3
Version 2.5.3 32_bit
Version 2.5.4
Version 2.5.4 32_bit
Version 2.5.5
Version 2.5.5 32_bit
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9
Version 2.6.0
Pidgin
Version 2.6.0
Version 2.6.1

Timeline

No history available yet.