First published: Tue May 12 2009(Updated: )
The integer overflow fix for <a href="https://access.redhat.com/security/cve/CVE-2008-2927">CVE-2008-2927</a> was incomplete on 32 bit platforms. If a Pidgin user can receive a specially crafted MSN message, it may be possible to execute arbitrary code with the permissions of the user running Pidgin. This flaw is only exploitable by individuals who can message a user, which is controlled by the Pidgin privacy setting. The default setting is to only allow messages from users in the buddy list.
Affected Software | Affected Version | How to fix |
---|---|---|
Pidgin |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.