CVE-2009-3084

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
pidginpidgin
𝑥
≤ 2.6.1
pidginpidgin
2.0.0
pidginpidgin
2.0.1
pidginpidgin
2.0.2
pidginpidgin
2.0.2
pidginpidgin
2.1.0
pidginpidgin
2.1.1
pidginpidgin
2.2.0
pidginpidgin
2.2.1
pidginpidgin
2.2.2
pidginpidgin
2.3.0
pidginpidgin
2.3.1
pidginpidgin
2.4.0
pidginpidgin
2.4.0:32_bit
pidginpidgin
2.4.1
pidginpidgin
2.4.1:32_bit
pidginpidgin
2.4.2
pidginpidgin
2.4.2:32_bit
pidginpidgin
2.4.3
pidginpidgin
2.4.3:32_bit
pidginpidgin
2.5.0
pidginpidgin
2.5.0:32_bit
pidginpidgin
2.5.1
pidginpidgin
2.5.2
pidginpidgin
2.5.2:32_bit
pidginpidgin
2.5.3
pidginpidgin
2.5.3:32_bit
pidginpidgin
2.5.4
pidginpidgin
2.5.4:32_bit
pidginpidgin
2.5.5
pidginpidgin
2.5.5:32_bit
pidginpidgin
2.5.6
pidginpidgin
2.5.7
pidginpidgin
2.5.8
pidginpidgin
2.5.9
pidginpidgin
2.6.0
pidginlibpurple
2.6.0
pidginlibpurple
2.6.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pidgin
bullseye
2.14.1-1
fixed
bookworm
2.14.12-1
fixed
sid
2.14.13-2
fixed
trixie
2.14.13-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pidgin
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne