CVE-2009-1889
EPSS 3.2%
Description
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
How to fix CVE-2009-1889
To remediate CVE-2009-1889, upgrade the affected package to a fixed version below.
- Debian/pidgin—upgrade to 2.5.8-1 or later
Is CVE-2009-1889 being exploited?
Low — EPSS is 3.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.5.8-1