First published: Wed May 23 2012(Updated: )
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pidgin-OTR | <=3.2.0 | |
Pidgin |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2369 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2012-2369, upgrade the Off-the-Record Messaging plugin to version 3.2.1 or later.
CVE-2012-2369 affects the Pidgin-OTR plugin versions prior to 3.2.1.
Yes, CVE-2012-2369 can be exploited remotely through malicious format string specifiers.
The impact of CVE-2012-2369 includes the potential for arbitrary code execution, compromising system integrity.