vendor:
libpurple, pidgin, and pidgin-otr
by:
Dimitris Glynos
5,5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: libpurple, pidgin, and pidgin-otr
Affected Version From: libpurple versions prior to 2.10.1, pidgin versions prior to 2.10.1, pidgin-otr versions prior to 3.2.0
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2012-1257
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
libpurple Information Disclosure Vulnerability
libpurple is prone to an information-disclosure vulnerability. Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks. The following products are vulnerable: libpurple versions prior to 2.10.1, pidgin versions prior to 2.10.1, pidgin-otr versions prior to 3.2.0. A proof-of-concept code was released that snoops on pidgin discussions (OTR/non-OTR) via dbus.
Mitigation:
Upgrade to the latest version of libpurple, pidgin, and pidgin-otr.