Bugzilla – Bug 991708
VUL-0: CVE-2016-2375: pidgin: MXIT Suggested Contacts Memory Disclosure Vulnerability
Last modified: 2020-11-10 21:20:07 UTC
rh#1348880 An exploitable out-of-bounds ready exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure. External references: http://www.talosintel.com/reports/TALOS-2016-0143/ http://www.pidgin.im/news/security/?id=108 Upstream fixes: https://bitbucket.org/pidgin/main/commits/b786e9814536 References: https://bugzilla.redhat.com/show_bug.cgi?id=1348880
issue seems in sle11 and sle12.
bugbot adjusting priority
With Mxit officially shut down its services in 2016 and pidgin dropped support to the protocol since 2.12. Efforts to backport the fix won't make much sense. Discussed with Johannes and decided to close this as WONTFIX.