CVE-2010-0013
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
- Adium
- = 1.3.8
- Pidgin
- = 2.6.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 12.5% (96th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2010-01-09
CVE-2010-0013 at NVD
5 known exploits for CVE-2010-0013
Proof-of-concept code and exploit modules indexed by Sploitus