CVE-2016-10189: Null Pointer Dereference
Published Mar 14, 2017
·Updated
BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.
Affected Software
2 affected components
bitlbee BitlBee<=3.4.2
bitlbee bitlbee-libpurple<=3.5
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 14, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10189?
CVE-2016-10189 has a medium severity level due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2016-10189?
To fix CVE-2016-10189, upgrade to BitlBee version 3.5 or later.
3
What types of attacks can CVE-2016-10189 facilitate?
CVE-2016-10189 can facilitate denial of service attacks and potentially allow for arbitrary code execution.
4
Which versions of BitlBee are affected by CVE-2016-10189?
CVE-2016-10189 affects BitlBee versions prior to 3.5 and BitlBee-libpurple up to and including 3.4.2.
5
Can CVE-2016-10189 be exploited remotely?
Yes, CVE-2016-10189 can be exploited remotely through a malicious file transfer request.