Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-2694


The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.


Published

2009-08-21T11:02:41.890

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adium adium ≤ 1.3.5 Yes
Application adium adium 1.2.7 Yes
Application adium adium 1.3 Yes
Application adium adium 1.3.1 Yes
Application adium adium 1.3.2 Yes
Application adium adium 1.3.3 Yes
Application adium adium 1.3.4 Yes
Application pidgin pidgin ≤ 2.5.8 Yes
Application pidgin pidgin 2.0.0 Yes
Application pidgin pidgin 2.0.1 Yes
Application pidgin pidgin 2.0.2 Yes
Application pidgin pidgin 2.1.0 Yes
Application pidgin pidgin 2.1.1 Yes
Application pidgin pidgin 2.2.0 Yes
Application pidgin pidgin 2.2.1 Yes
Application pidgin pidgin 2.2.2 Yes
Application pidgin pidgin 2.3.0 Yes
Application pidgin pidgin 2.3.1 Yes
Application pidgin pidgin 2.4.0 Yes
Application pidgin pidgin 2.4.1 Yes
Application pidgin pidgin 2.4.2 Yes
Application pidgin pidgin 2.4.3 Yes
Application pidgin pidgin 2.5.0 Yes
Application pidgin pidgin 2.5.1 Yes
Application pidgin pidgin 2.5.2 Yes
Application pidgin pidgin 2.5.3 Yes
Application pidgin pidgin 2.5.4 Yes
Application pidgin pidgin 2.5.6 Yes
Application pidgin pidgin 2.5.7 Yes

References