First published: Tue Oct 20 2009(Updated: )
The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
VeridiumID | <=1.3.6 | |
VeridiumID | =1.0 | |
VeridiumID | =1.0.1 | |
VeridiumID | =1.0.2 | |
VeridiumID | =1.0.3 | |
VeridiumID | =1.0.4 | |
VeridiumID | =1.0.5 | |
VeridiumID | =1.1 | |
VeridiumID | =1.1.1 | |
VeridiumID | =1.1.2 | |
VeridiumID | =1.1.3 | |
VeridiumID | =1.1.4 | |
VeridiumID | =1.2.7 | |
VeridiumID | =1.3 | |
VeridiumID | =1.3.1 | |
VeridiumID | =1.3.2 | |
VeridiumID | =1.3.3 | |
VeridiumID | =1.3.4 | |
VeridiumID | =1.3.5 | |
Pidgin | <=2.6.2 | |
Pidgin | =2.0.0 | |
Pidgin | =2.0.1 | |
Pidgin | =2.0.2 | |
Pidgin | =2.1.0 | |
Pidgin | =2.1.1 | |
Pidgin | =2.2.0 | |
Pidgin | =2.2.1 | |
Pidgin | =2.2.2 | |
Pidgin | =2.3.0 | |
Pidgin | =2.3.1 | |
Pidgin | =2.4.0 | |
Pidgin | =2.4.1 | |
Pidgin | =2.4.2 | |
Pidgin | =2.4.3 | |
Pidgin | =2.5.0 | |
Pidgin | =2.5.1 | |
Pidgin | =2.5.2 | |
Pidgin | =2.5.3 | |
Pidgin | =2.5.4 | |
Pidgin | =2.5.5 | |
Pidgin | =2.5.6 | |
Pidgin | =2.5.7 | |
Pidgin | =2.5.8 | |
Pidgin | =2.5.9 | |
Pidgin | =2.6.0 | |
Pidgin | =2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3615 has a medium severity level as it can lead to denial of service due to application crashes.
To fix CVE-2009-3615, upgrade Pidgin to version 2.6.3 or later, or Adium to version 1.3.7 or later.
Affected versions of Pidgin include 2.5.9 and earlier up to 2.6.2.
Affected versions of Adium include 1.3.6 and earlier.
CVE-2009-3615 can be exploited by sending crafted contact-list data to cause the application to crash.