suse · CVE-2017-2640

Quick triage

Priority: high Published: 2021-05-30 13:50:21 UTC Updated: 2023-12-09 01:09:44 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-2640 severity important: SUSE including 90 source package names (finch, finch-2.10.11-5.el7, …), 176 product×package rows across 22 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise Desktop 12 SP3, … (22 product lines)): Fixed 131, Known Not Affected 45.

Description:

An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.

cvelogic Threat Intelligence