CVE-2015-8833: Use After Free
Published Apr 8, 2016
·Updated
Use-after-free vulnerability in the createsmpdialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item.
Affected Software
1 affected component
cypherpunks Pidgin-otr<=4.0.1
Event History
Apr 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8833?
CVE-2015-8833 is classified as a critical severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2015-8833?
To fix CVE-2015-8833, upgrade the Pidgin-OTR plugin to version 4.0.2 or later.
3
What systems are affected by CVE-2015-8833?
CVE-2015-8833 affects the Pidgin-OTR plugin versions prior to 4.0.2 for the Pidgin application.
4
Can CVE-2015-8833 be exploited remotely?
Yes, CVE-2015-8833 can be exploited remotely through malicious interactions via the 'Authenticate buddy' menu item.
5
What vulnerability type is CVE-2015-8833?
CVE-2015-8833 is categorized as a use-after-free vulnerability.