cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pidgin | Jul 30, 2024 | Aug 8, 2012 |
| Oracle_linux | — | Upgrade pidgin-develUpgrade libpurple-develUpgrade libpurple-perlUpgrade finchUpgrade libpurpleUpgrade libpurple-tclUpgrade finch-develUpgrade pidgin-perlUpgrade pidgin-docsUpgrade pidgin | Oct 16, 2024 | Aug 8, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 10, 2011 |
| Ubuntu | — | Upgrade libpurple0Upgrade pidginUpgrade finch | Nov 8, 2024 | Aug 8, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub