CVE-2012-1257 describes an information disclosure vulnerability in Pidgin 2.10.0, where the application uses DBUS for cleartext communication, allowing local attackers to intercept sensitive information via a dbus session monitor. This medium-severity vulnerability (CVSS 5.5) requires local access and low privileges, potentially leading to high confidentiality impact without affecting integrity or availability. While not actively exploited in the wild or on CISA's KEV catalog, an ExploitDB entry (EDB-36884) exists for a related libpurple OTR information disclosure, and there is minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10.0CPE matchmatch criteria | cpe:2.3:a:pidgin:pidgin:2.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.