CVE-2009-3083

The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
pidginlibpurple
*
pidginpidgin
𝑥
≤ 2.6.1
pidginpidgin
2.0.0
pidginpidgin
2.0.1
pidginpidgin
2.0.2
pidginpidgin
2.0.2
pidginpidgin
2.1.0
pidginpidgin
2.1.1
pidginpidgin
2.2.0
pidginpidgin
2.2.1
pidginpidgin
2.2.2
pidginpidgin
2.3.0
pidginpidgin
2.3.1
pidginpidgin
2.4.0
pidginpidgin
2.4.0:32_bit
pidginpidgin
2.4.1
pidginpidgin
2.4.1:32_bit
pidginpidgin
2.4.2
pidginpidgin
2.4.2:32_bit
pidginpidgin
2.4.3
pidginpidgin
2.4.3:32_bit
pidginpidgin
2.5.0
pidginpidgin
2.5.0:32_bit
pidginpidgin
2.5.1
pidginpidgin
2.5.2
pidginpidgin
2.5.2:32_bit
pidginpidgin
2.5.3
pidginpidgin
2.5.3:32_bit
pidginpidgin
2.5.4
pidginpidgin
2.5.4:32_bit
pidginpidgin
2.5.5
pidginpidgin
2.5.5:32_bit
pidginpidgin
2.5.6
pidginpidgin
2.5.7
pidginpidgin
2.5.8
pidginpidgin
2.5.9
pidginpidgin
2.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pidgin
bullseye
2.14.1-1
fixed
bookworm
2.14.12-1
fixed
sid
2.14.13-2
fixed
trixie
2.14.13-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pidgin
karmic
not-affected
jaunty
Fixed 1:2.5.5-1ubuntu8.5
released
intrepid
Fixed 1:2.5.2-0ubuntu1.6
released
hardy
Fixed 1:2.4.1-1ubuntu2.8
released
dapper
dne