This application requires Javascript for optimal performance.

Libpurple.MSNSLP.Buffer.Overflow

Release Date

Sep 08, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer overflow vulnerability in Pidgin.

The vulnerability is caused by an error when the vulnerable software handles a malicious message. It allows a remote attacker to execute arbitrary code via sending crafted msn message.

Affected Products

Gaim >= 0.79
Libpurple <= 2.5.8 (Pidgin <= 2.5.8 and Adium <= 1.3.5)
Other Libpurple frontends such as Finch might be vulnerable as well.

Recommended Actions

Upgrade to the latest version, Libpurple >= 2.6.0 (Pidgin >= 2.6.0)

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2694

Reference/s

http://www.coresecurity.com/content/libpurple-arbitrary-write

Reference: VID-17683