Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pidgin | Jul 30, 2024 | Sep 5, 2018 |
| Gentoo Linux | — | Upgrade net-im/pidgin. | Oct 30, 2017 | Jan 17, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libpurple | Nov 3, 2020 | Sep 5, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libpurple | Sep 28, 2020 | Sep 5, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libpurple | Nov 2, 2020 | Sep 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub