CVE-2016-1000030 Information
Feb 14, 2021
cve
Description
Pidgin version 2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://access.redhat.com/security/cve/cve-2016-1000030 https://bitbucket.org/pidgin/main/commits/d6fc1ce76ffe https://pidgin.im/news/security/?id=91 https://security.gentoo.org/glsa/201701-38 https://www.suse.com/pt-br/security/cve/CVE-2016-1000030/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: