VDB
CVE-2010-0013
CVE-2010-0013
PUBLISHED
CVSS 7.5 HIGH
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
EPSS 12.50% · 95.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
12.50%
95.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| opensuse | opensuse | 11.0 |
| redhat | enterprise_linux | 4.0, 5.0 |
| suse | linux_enterprise | 11.0 |
| pidgin | pidgin | 2.6.4 |
| suse | linux_enterprise_server | 10, 10 |
| adium | adium | 1.3.8 |
| fedoraproject | fedora | 12, 11 |
| n/a | n/a | n/a |
Timeline
- Jan 9, 2010 CVE Published
- Jan 19, 2010 PoC Published
- Jan 19, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 25, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 277450 vendor-advisory
- SUSE-SR:2010:006 vendor-advisory
- http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810 url
- 37961 third-party-advisory
- 37954 third-party-advisory
- [oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload mailing-list
- oval:org.mitre.oval:def:17620 vdb
- ADV-2010-1020 vdb
- 38915 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-0013 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=552483 url
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333 url
- http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c url
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1 url
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:085 url
- http://www.openwall.com/lists/oss-security/2010/01/07/2 url
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.html mailing_list
- http://www.openwall.com/lists/oss-security/2010/01/02/1 mailing_list
- http://www.vupen.com/english/advisories/2009/3662 technical
- http://www.vupen.com/english/advisories/2009/3663 technical
…and 5 more