Name | CVE-2016-2371 |
Description | An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-542-1, DSA-3620-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
pidgin (PTS) | bullseye | 2.14.1-1 | fixed |
| bookworm | 2.14.12-1 | fixed |
| sid, trixie | 2.14.13-2 | fixed |
The information below is based on the following data on fixed versions.
Notes
http://www.talosintel.com/reports/TALOS-2016-0139/
http://www.pidgin.im/news/security/?id=104
https://bitbucket.org/pidgin/main/commits/f0287378203fbf496a9890bf273d96adefb93b74