CVE-2016-2375: Medium severity pidgin vulnerability
Published Jan 6, 2017
·Updated
An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
Affected Software
5 affected components
Pidgin Pidgin<=2.10.12
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jan 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2375?
CVE-2016-2375 is classified as a medium severity vulnerability due to its potential for memory disclosure.
2
How do I fix CVE-2016-2375?
To fix CVE-2016-2375, update Pidgin to version 2.10.12 or later.
3
What types of software are affected by CVE-2016-2375?
CVE-2016-2375 affects Pidgin versions up to and including 2.10.12, as well as Ubuntu 12.04, 14.04, 15.10, and Debian 8.0.
4
What impact does CVE-2016-2375 have on users?
CVE-2016-2375 can lead to memory disclosure, potentially exposing sensitive information to attackers.
5
Is there a workaround for CVE-2016-2375?
There is no known workaround for CVE-2016-2375; updating to the latest version is the recommended solution.