CVE-2008-2957: Input Validation
Published Jul 1, 2008
·Updated
The UPnP functionality in Pidgin 2.0.0, and possibly other versions, allows remote attackers to trigger the download of arbitrary files and cause a denial of service (memory or disk consumption) via a UDP packet that specifies an arbitrary URL.
Affected Software
1 affected component
Pidgin Pidgin=2.0.0
Event History
Jul 1, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2957?
CVE-2008-2957 is considered a moderate to high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2008-2957?
To fix CVE-2008-2957, upgrade Pidgin to the latest version that has addressed this vulnerability.
3
What type of attack is associated with CVE-2008-2957?
CVE-2008-2957 is associated with remote attacks that exploit UPnP functionality to download arbitrary files.
4
Which versions of Pidgin are affected by CVE-2008-2957?
CVE-2008-2957 specifically affects Pidgin version 2.0.0 and possibly other versions.
5
What impact can CVE-2008-2957 have on my system?
CVE-2008-2957 can lead to significant memory or disk consumption, resulting in denial of service.