Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pidgin-otr | Jul 30, 2024 | May 23, 2012 |
| Freebsd | — | Upgrade pidgin-otr | Dec 10, 2025 | May 16, 2012 |
| Gentoo Linux | — | Upgrade x11-plugins/pidgin-otr. | Oct 30, 2017 | May 23, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | May 23, 2012 |
| Suse | — | Upgrade pidgin-plugin-otrUpgrade pidgin-plugin-otr-langUpgrade pidgin-otr | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade pidgin-otr | Nov 19, 2024 | May 23, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub