VDB
CVE-2012-2369
CVE-2012-2369
PUBLISHED
CVSS 7.5 HIGH
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
EPSS 3.52% · 88.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.52%
88.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cypherpunks | pidgin-otr | 0 |
| n/a | n/a | n/a |
Timeline
- May 23, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- GLSA-201207-05 vendor-advisory
- DSA-2476 vendor-advisory
- [oss-security] 20120516 Format string security flaw in pidgin-otr mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2012-2369 advisory
- http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00003.html url