VDB
CVE-2009-1376
CVE-2009-1376
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
EPSS 13.29% · 96.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
13.29%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| pidgin | pidgin | 2.4.2, 2.4.1, 2.4.3 |
Timeline
- May 26, 2009 CVE Published
- Sep 9, 2009 PoC Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Aug 29, 2023 EPSS Score
- Oct 13, 2023 EPSS Score
References
- oval:org.mitre.oval:def:10476 vdb
- http://www.pidgin.im/news/security/?id=32 url
- RHSA-2009:1060 vendor-advisory
- USN-781-2 vendor-advisory
- RHSA-2009:1059 vendor-advisory
- FEDORA-2009-5583 vendor-advisory
- oval:org.mitre.oval:def:18432 vdb
- 37071 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=500493 url
- DSA-1805 vendor-advisory
- MDVSA-2009:140 vendor-advisory
- 35188 third-party-advisory
- FEDORA-2009-5552 vendor-advisory
- 35215 third-party-advisory
- 35330 third-party-advisory
- MDVSA-2009:173 vendor-advisory
- FEDORA-2009-5597 vendor-advisory
- GLSA-200905-07 vendor-advisory
- 35067 vdb
- 35329 third-party-advisory
…and 7 more