CVE-2013-6481

Priority
Medium
Description
libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote
attackers to cause a denial of service (crash) via a Yahoo! P2P message
with a crafted length field, which triggers a buffer over-read.
References
Assigned-to
mdeslaur
Package
Upstream:released (2.10.8)
Ubuntu 12.04 LTS (Precise Pangolin):released (1:2.10.3-0ubuntu1.4)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:2.10.9-0ubuntu1)
Patches:
Upstream:http://hg.pidgin.im/pidgin/main/rev/4d139ce8f7ec
More Information

Valid XHTML 1.0 Strict

Updated: 2015-07-29 20:42:06 UTC (commit 9756)