CVE-2009-3084: Input Validation
The msnslpprocessmsg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3084?
CVE-2009-3084 has a severity rating associated with it due to its potential to cause a denial of service for affected versions of Pidgin.
How do I fix CVE-2009-3084?
To fix CVE-2009-3084, you should upgrade Pidgin to version 2.6.2 or later.
Which versions of Pidgin are affected by CVE-2009-3084?
CVE-2009-3084 affects Pidgin versions from 2.0.0 up to and including 2.6.1.
What type of vulnerability is CVE-2009-3084?
CVE-2009-3084 is a denial of service vulnerability that leads to application crashes.
Can CVE-2009-3084 be exploited remotely?
Yes, CVE-2009-3084 can be exploited remotely through specially crafted messages.