CVE-2017-2640 log

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
An out-of-bounds write has been found in libpurple < 2.12.0 in the purple_markup_unescape_entity function. This issue can be triggered by a malicious server sending invalid XML entities separated by whitespace, eg "&#3000;" to the client.
Group Package Affected Fixed Severity Status Ticket
AVG-226 libpurple 2.11.0-2 2.12.0-1 High Fixed
Date Advisory Group Package Severity Type
21 Mar 2017 ASA-201703-18 AVG-226 libpurple High arbitrary code execution
References
http://seclists.org/fulldisclosure/2017/Mar/57
https://www.pidgin.im/news/security/?id=109
https://bitbucket.org/pidgin/main/commits/b2fc9e774cb9