First published: Tue Jul 01 2008(Updated: )
Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pidgin | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2955 is classified as a denial of service vulnerability.
CVE-2008-2955 exploits occur when remote attackers send a long filename through MSN messages that causes Pidgin to crash.
CVE-2008-2955 specifically affects Pidgin version 2.4.1.
To mitigate CVE-2008-2955, you should upgrade to a newer version of Pidgin beyond 2.4.1.
The potential impacts of CVE-2008-2955 include application crashes and disruption of service for users of Pidgin.