CVE-2010-0013

Publication date 9 January 2010

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.

Read the notes from the security team

Status

Package Ubuntu Release Status
pidgin 9.10 karmic
Fixed 1:2.6.2-1ubuntu7.1
9.04 jaunty
Fixed 1:2.5.5-1ubuntu8.5
8.10 intrepid
Fixed 1:2.5.2-0ubuntu1.6
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release

Notes


mdeslaur

pidgin in hardy doesn't support MSN_OBJECT_EMOTICON

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N