suse · CVE-2016-1000030

Quick triage

Priority: medium Published: 2021-05-30 13:49:48 UTC Updated: 2025-11-05 04:12:10 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-1000030 severity moderate: SUSE including 10 source package names (finch, finch-devel, …), 20 product×package rows across 3 product lines (SUSE Linux Enterprise Desktop 12 SP3, SUSE Linux Enterprise Software Development Kit 12 SP3, SUSE Linux Enterprise Workstation Extension 12 SP3): Known Not Affected 20.

Description:

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

cvelogic Threat Intelligence