CVE-2016-2374: Infoleak
An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2374?
CVE-2016-2374 is considered a high severity vulnerability due to its potential for memory corruption, leading to code execution.
How do I fix CVE-2016-2374?
To mitigate CVE-2016-2374, it is recommended to update Pidgin to version 2.10.13 or later.
What software is affected by CVE-2016-2374?
CVE-2016-2374 affects Pidgin versions up to and including 2.10.12 and specific versions of Ubuntu and Debian Linux.
What are the consequences of exploiting CVE-2016-2374?
Exploiting CVE-2016-2374 can lead to memory disclosure and potentially the execution of arbitrary code.
Is CVE-2016-2374 remotely exploitable?
Yes, CVE-2016-2374 can be remotely exploited through specially crafted MXIT MultiMX messages sent via the server.