libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26205 | vdb entry |
http://www.pidgin.im/news/security/?id=24 | patch |
http://www.vupen.com/english/advisories/2007/3624 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18357 | vdb entry signature |
http://osvdb.org/38695 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38132 | vdb entry |
http://secunia.com/advisories/27495 | third party advisory |
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00011.html | vendor advisory |
http://www.securityfocus.com/archive/1/483580/100/0/threaded | mailing list |
http://secunia.com/advisories/27372 | third party advisory patch vendor advisory |
http://secunia.com/advisories/27858 | third party advisory |
http://www.ubuntu.com/usn/usn-548-1 | vendor advisory |