CVE-2010-0277: Medium severity veridiumid vulnerability
slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different issue than CVE-2010-0013.
Reference: URL:http://www.openwall.com/lists/oss-security/2010/01/07/2 Reference: MISC:http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
Other sources
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0277?
CVE-2010-0277 is classified as a denial of service vulnerability that can lead to memory corruption.
How do I fix CVE-2010-0277?
To mitigate CVE-2010-0277, users should upgrade to a patched version of Pidgin or Adium beyond the affected versions.
Which versions of Pidgin are affected by CVE-2010-0277?
CVE-2010-0277 affects Pidgin versions 2.6.4 and earlier, including all versions from 2.0.0 to 2.6.4.
Which version of Adium is vulnerable to CVE-2010-0277?
CVE-2010-0277 specifically affects Adium version 1.3.8.
What is the potential impact of CVE-2010-0277?
The primary impact of CVE-2010-0277 is a denial of service which can disrupt normal operation of the affected applications.