CVE-2012-2369
pidgin-otr - format string vulnerability
EPSS 3.6%
Description
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
How to fix CVE-2012-2369
To remediate CVE-2012-2369, upgrade the affected package to a fixed version below.
- Debian/pidgin-otr—upgrade to 3.2.1-1 or later
- Debian/pidgin-otr—upgrade to 3.2.0-5+squeeze1 or later
Is CVE-2012-2369 being exploited?
Low — EPSS is 3.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.2.1-1
- from 0, < 3.2.0-5+squeeze1