Your submission was sent successfully! Close

CVE-2013-6479

Published: 5 February 2014

util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.

Priority

Medium

Status

Package Release Status
pidgin
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise
Released (1:2.10.3-0ubuntu1.4)
quantal
Released (1:2.10.6-0ubuntu2.3)
saucy
Released (1:2.10.7-0ubuntu4.1.13.10.1)
upstream
Released (2.10.8)