CVE-2016-2376 describes a buffer overflow vulnerability in Pidgin's handling of the MXIT protocol, affecting various Pidgin and associated Linux distributions. A malicious server or man-in-the-middle attacker could send specially crafted MXIT data with an invalid packet size, triggering the overflow. This vulnerability carries a high CVSS score of 8.1 due to its network-based attack vector, high impact on confidentiality, integrity, and availability, and the fact that no user interaction is required. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating its potential significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10.12CPE matchmatch criteria | cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.