CVE-2013-6484: Input Validation
The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a socket read error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6484?
CVE-2013-6484 has a moderate severity rating as it allows a denial of service via out-of-bounds write operations that may crash the application.
How do I fix CVE-2013-6484?
To fix CVE-2013-6484, upgrade to Pidgin version 2.10.8 or later where the vulnerability is patched.
Which versions of Pidgin are affected by CVE-2013-6484?
CVE-2013-6484 affects all Pidgin versions prior to 2.10.8.
What are the implications of CVE-2013-6484?
CVE-2013-6484 can allow remote STUN servers to trigger application crashes, leading to potential service disruptions.
Is there a workaround for CVE-2013-6484?
No specific workaround is recommended for CVE-2013-6484; the best mitigation is to update to the latest version of Pidgin.