CVE-2007-4996
EPSS 1.7%
Description
libpurple in Pidgin before 2.2.1 does not properly handle MSN nudge messages from users who are not on the receiver's buddy list, which allows remote attackers to cause a denial of service (crash) via a nudge message that triggers an access of "an invalid memory location."
How to fix CVE-2007-4996
To remediate CVE-2007-4996, upgrade the affected package to a fixed version below.
- Debian/pidgin—upgrade to 2.2.1-1 or later
Is CVE-2007-4996 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.2.1-1