Pidgin MXIT Markup Command Denial of... CVE-2016-2365 CNNVD-201606-530

4.3 AV AC AU C I A
发布: 2017-01-06
修订: 2017-03-30

### DESCRIPTION A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash. ### CVSSv3 SCORE 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H ### TESTED VERSIONS Pidgin 2.10.11 ### PRODUCT URLs https://www.pidgin.im/ ### DETAILS When handling markup commands there are insufficient checks to validate that all required fields have been provided to successfully execute the command, potentially resulting in a null pointer dereference when trying to use those values. When a command is received in a message, the function mxitparsecommand() is called. This function is defined at line 562 in the file mxit/formcmds.c. This function excepts to find values in the key=value format and will insert these pairs into a hashtable:...

0%
暂无可用Exp或PoC
当前有5条受影响产品信息