CVE-2016-2373: Medium severity pidgin vulnerability
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2373?
CVE-2016-2373 has been classified as a denial of service vulnerability.
How do I fix CVE-2016-2373?
To mitigate CVE-2016-2373, update to the latest version of Pidgin or a patched version provided by your distribution.
What software is affected by CVE-2016-2373?
CVE-2016-2373 affects Pidgin versions up to 2.10.12, and is also relevant for specific versions of Ubuntu and Debian.
Can CVE-2016-2373 be exploited remotely?
Yes, CVE-2016-2373 can be exploited remotely by sending specially crafted MXIT data from a malicious server.
What impact does CVE-2016-2373 have on users?
CVE-2016-2373 can potentially lead to an out-of-bounds read, resulting in a denial of service for users of the affected software.