Security Advisory

CVE-2009-3084

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-09-08 18:00:00
Last updated 2024-08-07 06:14:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.