Дата обнаружения
|
21/06/2016 |
Уровень угрозы
|
High |
Описание
|
Multiple serious vulnerabilities have been found in Pidgin. Malicious users can exploit these vulnerabilities to overwrite arbitrary files, cause denial of service, obtain sensitive information. Below is a complete list of vulnerabilities:
Technical details Vulnerability (1) occurs if liburple is triggered by man-in-the-middle or a malicious server to overwrite local files. The name and and content of these files can be specified by the remote attacker. To trigger vulnerability (3) a malicious server or man-in-the-middle can send negative length values. |
Пораженные продукты
|
Pidgin versions earlier than 2.11.0 |
Решение
|
Update to the latest version |
Первичный источник обнаружения
|
Pidgin Security Advisory |
Оказываемое влияние
?
|
OSI
[?]
DoS
[?]
OAF
[?]
|
Связанные продукты
|
Pidgin |
CVE-IDS
|
|
Узнай статистику распространения уязвимостей в твоем регионе |