PublicDateAtUSN: 2009-10-20 Candidate: CVE-2009-3615 PublicDate: 2009-10-20 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3615 http://www.pidgin.im/news/security/?id=41 https://ubuntu.com/security/notices/USN-886-1 Description: The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client. Ubuntu-Description: Notes: Bugs: http://developer.pidgin.im/ticket/10481 Priority: low Discovered-by: Assigned-to: CVSS: Patches_pidgin: upstream: http://developer.pidgin.im/viewmtn/revision/info/781682333aea0c801d280c3507ee25552a60bfc0 upstream_pidgin: released (2.6.3) dapper_pidgin: DNE hardy_pidgin: released (1:2.4.1-1ubuntu2.8) intrepid_pidgin: released (1:2.5.2-0ubuntu1.6) jaunty_pidgin: released (1:2.5.5-1ubuntu8.5) karmic_pidgin: released (1:2.6.2-1ubuntu7.1) devel_pidgin: not-affected (1:2.6.4-1ubuntu3)