CVE-2013-6485: Buffer Overflow
Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chunk-size field in chunked transfer-coding data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6485?
CVE-2013-6485 has been classified as a high severity vulnerability due to its potential to cause application crashes and denial of service.
How do I fix CVE-2013-6485?
To fix CVE-2013-6485, update Pidgin to version 2.10.8 or later.
What causes CVE-2013-6485?
CVE-2013-6485 is caused by a buffer overflow in the libpurple component of Pidgin due to improper handling of chunk-size fields in chunked transfer-coding data.
Which versions of Pidgin are affected by CVE-2013-6485?
Versions of Pidgin prior to 2.10.8, including all versions from 2.0.0 to 2.10.7, are affected by CVE-2013-6485.
What impact does CVE-2013-6485 have?
The impact of CVE-2013-6485 can result in application crashes and may potentially lead to other unspecified impacts.