Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3711

17
FAUCET Score

CVE-2010-3711 describes a denial-of-service vulnerability in libpurple, specifically affecting Pidgin versions prior to 2.7.4. The flaw stems from improper validation of the purple_base64_decode function's return value, allowing remote authenticated users to trigger a NULL pointer dereference and application crash through a crafted message. This vulnerability has a CVSS score of 4.0, indicating a low severity, with an attack vector over the network, low attack complexity, requiring authentication, and resulting in availability impact. There is no evidence of active exploitation, no known exploit code available in Metasploit or ExploitDB, and minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.7.3CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:2.0.0:*:*:*:*:*:*:*
2.0.1CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:2.0.1:*:*:*:*:*:*:*
2.0.2CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:2.0.2:*:*:*:*:*:*:*
2.1.0CPE matchmatch criteria
cpe:2.3:a:pidgin:pidgin:2.1.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.0MEDIUM

AV:N/AC:L/Au:S/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.27%
Probability of exploitation in next 30 days
EPSS Percentile
87.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0327 is in the 96th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: pidgin-0:2.6.6-5.el4_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: pidgin-0:2.6.6-5.el5_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: pidgin-0:2.6.6-6.el6_0
View patch

Vendor Advisories (1)

redhatCVE-2010-3711Moderate

(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values

Oct 20, 2010

References

developer.pidgin.im / viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcc
Patch
lists.fedoraproject.org / pipermail/package-announce/2010-November/050227.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/050695.html
lists.fedoraproject.org / pipermail/package-announce/2010-October/050133.html
pidgin.im / news/security
PatchVendor Advisory
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/41893
Vendor Advisory
secunia.com / advisories/41899
Vendor Advisory
secunia.com / advisories/42075
secunia.com / advisories/42294
securitytracker.com / id
exchange.xforce.ibmcloud.com / vulnerabilities/62708
slackware.com / security/viewer.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18506
mandriva.com / security/advisories
osvdb.org / 68773
redhat.com / support/errata/RHSA-2010-0788.html
redhat.com / support/errata/RHSA-2010-0890.html
securityfocus.com / bid/44283
ubuntu.com / usn/USN-1014-1
vupen.com / english/advisories/2010/2753
PatchVendor Advisory
vupen.com / english/advisories/2010/2754
Vendor Advisory
vupen.com / english/advisories/2010/2755
Vendor Advisory
vupen.com / english/advisories/2010/2847
vupen.com / english/advisories/2010/2851
vupen.com / english/advisories/2010/2870