1 results (0.002 seconds)

CVSS: 7.5EPSS: 1%CPEs: 48EXPL: 1

04 Nov 2011 — The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2. La función g_markup_escape_text en el complemento de protocolo SILC en libpurple v2.10.0 y anteriores, como se usa en Pidgin y posiblemente en otros productos, ... • http://developer.pidgin.im/ticket/14636 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •