CVE-2013-6479: Medium severity Pidgin Pidgin vulnerability
util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6479?
CVE-2013-6479 has a severity rating that allows remote attackers to cause denial of service through application crashes.
How do I fix CVE-2013-6479?
To fix CVE-2013-6479, users should upgrade to Pidgin version 2.10.8 or later.
Which versions of Pidgin are affected by CVE-2013-6479?
CVE-2013-6479 affects Pidgin versions prior to 2.10.8, including all versions from 2.0.0 to 2.10.7.
What type of vulnerability is CVE-2013-6479?
CVE-2013-6479 is a memory allocation vulnerability related to improper handling of HTTP responses.
Can CVE-2013-6479 be exploited remotely?
Yes, CVE-2013-6479 can be remotely exploited by sending crafted HTTP responses that cause application crashes.