CVE-2016-4323
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.
- Pidgin
- ≤ 2.10.12
- CVSS 2.0
- 5.8 MEDIUM
- CVSS 3.1
- 3.7 LOW
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2017-01-06
CVE-2016-4323 at NVD
1 known exploit for CVE-2016-4323
Proof-of-concept code and exploit modules indexed by Sploitus