Advertisement






Adium 1.5.10.2 libpurple Code Execution

CVE Category Price Severity
CVE-2017-2640 CWE-119 $5,000 - $25,000 High
Author Risk Exploitation Type Date
Marin Lemanto High Remote 2017-03-21
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.82142 0.808002

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017030191

Below is a copy:

Adium 1.5.10.2 libpurple Code ExecutionAdium is a popular instant messaging client for MacOS (OSX) that
incorporates libpurple. The current release (1.5.10.2) is vulnerable
to CVE-2017-2640 in libpurple, which permits execution of arbitrary
code on the client.

The Adium team has been aware of the vulnerability since at least
March 15, but has not released an advisory to its users, for reasons
unknown.

A post to the official developer's mailing list, which included
vulnerability information and queries about Adium's process for
handling upstream advisories from libpurple, has gone unanswered.
Adium's build process documentation does not seem to include steps for
upgrading or rebuilding libpurple, and the copy of libpurple checked
into Adium's open-source repository as a binary blob of unknown
provenance.

Eryt




Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum