VDB
CVE-2011-4602
CVE-2011-4602
PUBLISHED
CVSS 5 MEDIUM
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
EPSS 3.58% · 88.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
3.58%
88.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pidgin | pidgin | 2.0.1, 0, 2.0.0 |
| n/a | n/a | n/a |
Timeline
- Dec 17, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- RHSA-2011:1820 vendor-advisory
- openSUSE-SU-2012:0066 vendor-advisory
- http://pidgin.im/news/security/?id=58 url
- RHSA-2011:1821 vendor-advisory
- 47234 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4602 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18420 url
- http://secunia.com/advisories/47219 url
- http://developer.pidgin.im/viewmtn/revision/info/fb216fc88b085afc06d9a15209519cde1f4df6c6 technical