CVE-2016-2370: Medium severity pidgin vulnerability
Published Jan 6, 2017
·Updated
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability.
Affected Software
5 affected components
Pidgin Pidgin<=2.10.12
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jan 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2370?
CVE-2016-2370 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-2370?
To fix CVE-2016-2370, update Pidgin to version 2.10.12 or later.
3
Which versions of Pidgin are affected by CVE-2016-2370?
CVE-2016-2370 affects Pidgin versions up to and including 2.10.12.
4
Can CVE-2016-2370 be exploited remotely?
Yes, CVE-2016-2370 can be exploited remotely by a malicious server or man-in-the-middle attacker.
5
What protocols are involved in CVE-2016-2370?
CVE-2016-2370 involves a vulnerability in the handling of the MXIT protocol.