VDB
CVE-2009-1376
CVE-2009-1376
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
EPSS 25.89% · 96.4th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
25.89%
96.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| pidgin | pidgin | 2.4.2, 2.4.1, 2.4.3 |
Timeline
- May 26, 2009 CVE Published
- Sep 9, 2009 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Aug 29, 2023 EPSS Score
- Oct 13, 2023 EPSS Score
References
- FEDORA-2009-5597 vendor-advisory
- oval:org.mitre.oval:def:10476 vdb
- http://www.pidgin.im/news/security/?id=32 url
- RHSA-2009:1060 vendor-advisory
- USN-781-2 vendor-advisory
- RHSA-2009:1059 vendor-advisory
- GLSA-200905-07 vendor-advisory
- 35067 vdb
- FEDORA-2009-5583 vendor-advisory
- 35329 third-party-advisory
- USN-781-1 vendor-advisory
- oval:org.mitre.oval:def:18432 vdb
- 37071 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=500493 url
- DSA-1805 vendor-advisory
- MDVSA-2009:140 vendor-advisory
- 35294 third-party-advisory
- 35188 third-party-advisory
- 35194 third-party-advisory
- FEDORA-2009-5552 vendor-advisory
…and 7 more