CVE-2016-2376: Buffer Overflow
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attacker who intercepts the network traffic can send an invalid size for a packet which will trigger a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2376?
CVE-2016-2376 has a high severity level due to the potential for arbitrary code execution.
How do I fix CVE-2016-2376?
To fix CVE-2016-2376, upgrade Pidgin to the latest version that addresses this vulnerability.
What software is affected by CVE-2016-2376?
CVE-2016-2376 affects Pidgin versions up to 2.10.12 and specific versions of Ubuntu and Debian.
What type of vulnerability is CVE-2016-2376?
CVE-2016-2376 is a buffer overflow vulnerability that can be exploited through the MXIT protocol.
Can CVE-2016-2376 be exploited remotely?
Yes, CVE-2016-2376 can be exploited remotely by a malicious server sending specially crafted MXIT data.