PublicDateAtUSN: 2016-06-23 Candidate: CVE-2016-4323 PublicDate: 2017-01-06 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4323 http://www.talosintel.com/reports/TALOS-2016-0128/ http://www.pidgin.im/news/security/?id=97 https://ubuntu.com/security/notices/USN-3031-1 Description: A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Yves Younan Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N [3.7 LOW] Patches_pidgin: upstream: https://bitbucket.org/pidgin/main/commits/5fa3f2bc69d7 upstream_pidgin: released (2.11.0-1) precise_pidgin: released (1:2.10.3-0ubuntu1.7) trusty_pidgin: released (1:2.10.9-0ubuntu3.3) trusty/esm_pidgin: released (1:2.10.9-0ubuntu3.3) vivid/stable-phone-overlay_pidgin: DNE vivid/ubuntu-core_pidgin: DNE wily_pidgin: released (1:2.10.11-0ubuntu4.2) xenial_pidgin: released (1:2.10.12-0ubuntu5.1) devel_pidgin: released (1:2.10.12-0ubuntu6)