CVE-2016-2380: Infoleak
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2380?
CVE-2016-2380 has a moderate severity level due to the potential for an information leak in the MXIT protocol.
How do I fix CVE-2016-2380?
To fix CVE-2016-2380, users should update to the latest version of Pidgin or apply patches available for the affected versions.
Which versions of Pidgin are affected by CVE-2016-2380?
CVE-2016-2380 affects Pidgin versions up to and including 2.10.12.
On which operating systems does CVE-2016-2380 impact users?
CVE-2016-2380 primarily impacts users running Pidgin on Ubuntu 12.04, 14.04, 15.10, and Debian 8.0.
What should I do if I can't update my Pidgin due to system constraints related to CVE-2016-2380?
If unable to update Pidgin due to system constraints, consider removing MXIT support or monitoring for any exploit attempts related to CVE-2016-2380.