CVE-2016-2371

high

Description

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

References

https://security.gentoo.org/glsa/201701-38

http://www.ubuntu.com/usn/USN-3031-1

http://www.talosintelligence.com/reports/TALOS-2016-0139/

http://www.securityfocus.com/bid/91335

http://www.pidgin.im/news/security/?id=104

http://www.debian.org/security/2016/dsa-3620

Details

Source: Mitre, NVD

Published: 2017-01-06

Updated: 2017-03-30

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High