V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2009-1373
DEB
MediumConfirmedExploit available

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute ar…

CVSS
6.0
Medium
EPSS
0.04
p89
Published
2009-01-01
Updated
2009-01-01
Description

Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Pidgin ≤ 2.5.5Pidgin
CVSS vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Timeline
2009-01-01
Published
2009-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: S
Single
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.043 · p89
Known exploited (KEV)
No
Known exploits — Сканер-ВС
9615
exploitdb · https://www.exploit-db.com/exploits/9615
Enterprise
Affected products
ProductVendorStatus
gaimTracked
gaimTracked
pidginTracked
pidginTracked
pidginTracked
pidginTracked
pidginTracked
pidgin*Tracked
Source databases
DEB
CVE
RED
UBU