CVE-2014-3697

Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar archive of a smiley theme.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
pidginpidgin
𝑥
≤ 2.10.9
pidginpidgin
2.10.0
pidginpidgin
2.10.1
pidginpidgin
2.10.2
pidginpidgin
2.10.3
pidginpidgin
2.10.4
pidginpidgin
2.10.5
pidginpidgin
2.10.6
pidginpidgin
2.10.7
pidginpidgin
2.10.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pidgin
bookworm
2.14.12-1
fixed
bullseye
2.14.1-1
fixed
sid
2.14.13-2
fixed
trixie
2.14.13-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pidgin
lucid
ignored
precise
not-affected
trusty
not-affected
utopic
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
finch
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
libpurple
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-branding-upstream
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-client0
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-devel
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-lang
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-meanwhile
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
libpurple-plugin-sametime
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
libpurple-tcl
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
libpurple0
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
pidgin
suse enterprise desktop 12 SP2
2.11.0-12.5
fixed
suse enterprise desktop 12 SP3
2.12.0-1.33
fixed
suse enterprise desktop 12 SP4
2.12.0-3.3.1
fixed
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 12 SP2
2.11.0-12.5
fixed
suse enterprise sap 12 SP3
2.12.0-1.33
fixed
suse enterprise sap 12 SP4
2.12.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.12.0-3.3.1
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 12 SP2
2.11.0-12.5
fixed
suse enterprise server 12 SP3
2.12.0-1.33
fixed
suse enterprise server 12 SP4
2.12.0-3.3.1
fixed
suse enterprise server 12 SP5
2.12.0-3.3.1
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 12 SP2
2.11.0-12.5
fixed
suse enterprise workstation 12 SP3
2.12.0-1.33
fixed
suse enterprise workstation 12 SP4
2.12.0-3.3.1
fixed
suse enterprise workstation 12 SP5
2.12.0-3.3.1
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed
pidgin-devel
suse enterprise desktop 15
2.13.0-3.35
fixed
suse enterprise desktop 15 SP1
2.13.0-3.35
fixed
suse enterprise desktop 15 SP2
2.13.0-10.105
fixed
suse enterprise desktop 15 SP3
2.13.0-10.105
fixed
suse enterprise desktop 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise sap 15
2.13.0-3.35
fixed
suse enterprise sap 15 SP1
2.13.0-3.35
fixed
suse enterprise sap 15 SP2
2.13.0-10.105
fixed
suse enterprise sap 15 SP3
2.13.0-10.105
fixed
suse enterprise sap 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise server 15
2.13.0-3.35
fixed
suse enterprise server 15 SP1
2.13.0-3.35
fixed
suse enterprise server 15 SP2
2.13.0-10.105
fixed
suse enterprise server 15 SP3
2.13.0-10.105
fixed
suse enterprise server 15 SP4
2.14.8-150400.1.10
fixed
suse enterprise workstation 15
2.13.0-3.35
fixed
suse enterprise workstation 15 SP1
2.13.0-3.35
fixed
suse enterprise workstation 15 SP2
2.13.0-10.105
fixed
suse enterprise workstation 15 SP3
2.13.0-10.105
fixed
suse enterprise workstation 15 SP4
2.14.8-150400.1.10
fixed