← Back

CVE-2009-3085

nvd nist
Published: Sep 8, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.

Affected (37)

Products: Pidgin: Libpurple, Pidgin
2 products
Libpurple
Pidgin
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Pidgin
Up to 2.6.1
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0.2
Version 2.1.0
Version 2.1.1
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.3.0
Version 2.3.1
Version 2.4.0
Version 2.4.0 32_bit
Version 2.4.1
Version 2.4.1 32_bit
Version 2.4.2
Version 2.4.2 32_bit
Version 2.4.3
Version 2.4.3 32_bit
Version 2.5.0
Version 2.5.0 32_bit
Version 2.5.1
Version 2.5.2
Version 2.5.2 32_bit
Version 2.5.3
Version 2.5.3 32_bit
Version 2.5.4
Version 2.5.4 32_bit
Version 2.5.5
Version 2.5.5 32_bit
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9
Version 2.6.0

Timeline

No history available yet.