CVE-2013-6486: Input Validation
gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction of an explorer.exe command. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3185.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pidgin (gtkutils.c)to a version that resolves this vulnerability.Fixed in 2.10.8
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6486?
CVE-2013-6486 has a medium severity rating due to its ability to allow remote attackers to execute arbitrary commands via malicious file URLs.
How do I fix CVE-2013-6486?
To fix CVE-2013-6486, upgrade Pidgin to version 2.10.8 or later.
What versions of Pidgin are affected by CVE-2013-6486?
CVE-2013-6486 affects Pidgin versions up to and including 2.10.7.
What is the impact of exploiting CVE-2013-6486?
Exploiting CVE-2013-6486 can lead to unauthorized execution of commands on the victim's machine.
Is CVE-2013-6486 specific to any operating system?
Yes, CVE-2013-6486 primarily affects the Windows version of Pidgin.