CVE Database
/

CVE-2009-2694

Back to search

CVE-2009-2694

Published: Aug 20, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2009-2303
vdb-entry
x_refsource_VUPEN
36392
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:6320
vdb-entry
signature
x_refsource_OVAL
36402
third-party-advisory
x_refsource_SECUNIA
266908
vendor-advisory
x_refsource_SUNALERT
36384
third-party-advisory
x_refsource_SECUNIA
DSA-1870
vendor-advisory
x_refsource_DEBIAN
37071
third-party-advisory
x_refsource_SECUNIA
36708
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2663
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:10319
vdb-entry
signature
x_refsource_OVAL
36401
third-party-advisory
x_refsource_SECUNIA
9615
exploit
x_refsource_EXPLOIT-DB
RHSA-2009:1218
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now