CVE-2017-2640 - log back

CVE-2017-2640 created at 25 Sep 2019 19:31:40
Severity
+ High
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ An out-of-bounds write has been found in libpurple < 2.12.0 in the purple_markup_unescape_entity function. This issue can be triggered by a malicious server sending invalid XML entities separated by whitespace, eg "&#3000;" to the client.
References
+ http://seclists.org/fulldisclosure/2017/Mar/57
+ https://www.pidgin.im/news/security/?id=109
+ https://bitbucket.org/pidgin/main/commits/b2fc9e774cb9
Notes