CVE-2009-1374: Buffer Overflow
A denial-of-service flaw was found in pidgin's QQ protocol handler. When the QQ protocol decrypts packet information, a heap based buffer overflow results, which could cause pidgin to crash.
Other sources
Buffer overflow in the decryptout function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1374?
CVE-2009-1374 has a severity rating of medium due to its potential to cause denial-of-service.
How do I fix CVE-2009-1374?
To fix CVE-2009-1374, update Pidgin to version 2.5.6 or later.
What versions of Pidgin are affected by CVE-2009-1374?
CVE-2009-1374 affects versions of Pidgin prior to 2.5.6, including 2.5.5 and earlier versions.
What type of vulnerability is CVE-2009-1374?
CVE-2009-1374 is identified as a heap-based buffer overflow vulnerability.
Can CVE-2009-1374 be exploited by remote attackers?
Yes, CVE-2009-1374 can be exploited by remote attackers through the QQ protocol.