← All CVEs

CVE-2009-1376

high · 9.3

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.

9.3
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2009-05-26
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
pidginpidgin<= 2.5.5
pidginpidgin2.4.0
pidginpidgin2.4.1
pidginpidgin2.4.2
pidginpidgin2.4.3
pidginpidgin2.5.0
pidginpidgin2.5.2
pidginpidgin2.5.3
pidginpidgin2.5.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1376