AVG-226

Package libpurple
Status Fixed
Severity High
Type arbitrary code execution
Affected 2.11.0-2
Fixed 2.12.0-1
Current 2.13.0-2 [extra]
Ticket None
Created Tue Mar 21 13:52:57 2017
Issue Severity Remote Type Description
CVE-2017-2640 High Yes Arbitrary code execution
An out-of-bounds write has been found in libpurple < 2.12.0 in the purple_markup_unescape_entity function. This issue can be triggered by a malicious server...
Date Advisory Package Description
21 Mar 2017 ASA-201703-18 libpurple arbitrary code execution
References
http://seclists.org/fulldisclosure/2017/Mar/57
https://www.pidgin.im/news/security/?id=109
https://bitbucket.org/pidgin/main/commits/b2fc9e774cb9