Loading HuntDB...

GHSA-5mwr-c2hc-vr2x

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

Related CVEs

Key Information

GHSA ID
GHSA-5mwr-c2hc-vr2x
Published
May 17, 2022 2:52 AM
Last Modified
April 20, 2025 3:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.