CVE-2016-2366: Medium severity pidgin vulnerability
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2366?
CVE-2016-2366 is classified as a denial of service vulnerability.
How do I fix CVE-2016-2366?
Updating to a newer version of Pidgin beyond 2.10.12 can mitigate CVE-2016-2366.
Which software is affected by CVE-2016-2366?
CVE-2016-2366 affects Pidgin versions up to 2.10.12 and specific Debian and Ubuntu Linux distributions.
Can CVE-2016-2366 be exploited remotely?
Yes, CVE-2016-2366 can be exploited by sending specially crafted MXIT data from a malicious server.
What type of attack is CVE-2016-2366 related to?
CVE-2016-2366 is related to denial of service attacks that exploit out-of-bounds reads.