CVE-2010-3088: Code Injection
Published Oct 8, 2010
·Updated
The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message.
Affected Software
5 affected components
Jianping Yu Pidgin-knotify<=0.2.1
Jianping Yu Pidgin-knotify=0.1
Jianping Yu Pidgin-knotify=0.1.2
Jianping Yu Pidgin-knotify=0.2.0
Pidgin Pidgin
Event History
Oct 8, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
09:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-3088?
CVE-2010-3088 is considered a high-severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2010-3088?
To fix CVE-2010-3088, upgrade the pidgin-knotify plugin to version 0.2.2 or later.
3
Who is affected by CVE-2010-3088?
Users of pidgin-knotify plugin version 0.2.1 and earlier are affected by CVE-2010-3088.
4
What type of vulnerability is CVE-2010-3088?
CVE-2010-3088 is a remote code execution vulnerability.
5
What could attackers do using CVE-2010-3088?
Attackers could execute arbitrary commands on the victim's system via crafted messages.