CVE-2016-2368
Last modified
CVE-2016-2368 is a vulnerability of currently unknown severity. Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could result in multiple buffer overflows, potentially resulting in code execution or memory disclosure.. EPSS estimates a 4.52% chance of exploitation in the next 30 days.
Description
Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could result in multiple buffer overflows, potentially resulting in code execution or memory disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pidgin | Pidgin | <= 2.10.12 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 15.10 |
| Debian | Debian Linux | 8.0 |
References
- http://www.debian.org/security/2016/dsa-3620Third Party Advisory
- http://www.pidgin.im/news/security/?id=101Patch, Vendor Advisory
- http://www.securityfocus.com/bid/91335Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0136/Technical Description, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3031-1Third Party Advisory
- http://www.debian.org/security/2016/dsa-3620Third Party Advisory
- http://www.pidgin.im/news/security/?id=101Patch, Vendor Advisory
- http://www.securityfocus.com/bid/91335Third Party Advisory, VDB Entry
- http://www.talosintelligence.com/reports/TALOS-2016-0136/Technical Description, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3031-1Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2368?
How severe is CVE-2016-2368?
How do I fix CVE-2016-2368?
Are you affected by CVE-2016-2368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
