CVE-2016-2372 - CERT CVE
ID CVE-2016-2372
Sažetak An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.
Reference
CVSS
Base: 4.9
Impact: 4.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE PARTIAL
CVSS vektor AV:N/AC:M/Au:S/C:P/I:N/A:P
Zadnje važnije ažuriranje 30-03-2017 - 01:59
Objavljeno 06-01-2017 - 21:59