CVE-2012-2369: High severity pidgin-otr vulnerability
Published May 23, 2012
·Updated
Format string vulnerability in the logmessagecb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
Affected Software
2 affected components
cypherpunks Pidgin-otr<=3.2.0
Pidgin Pidgin
Remediation
Patch Available
Event History
May 23, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2369?
CVE-2012-2369 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2012-2369?
To fix CVE-2012-2369, upgrade the Off-the-Record Messaging plugin to version 3.2.1 or later.
3
What software is affected by CVE-2012-2369?
CVE-2012-2369 affects the Pidgin-OTR plugin versions prior to 3.2.1.
4
Can CVE-2012-2369 be exploited remotely?
Yes, CVE-2012-2369 can be exploited remotely through malicious format string specifiers.
5
What is the impact of CVE-2012-2369?
The impact of CVE-2012-2369 includes the potential for arbitrary code execution, compromising system integrity.