gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
References
Link Providers
http://developer.pidgin.im/wiki/ChangeLog cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html cve-icon cve-icon
http://pidgin.im/news/security/?id=45 cve-icon cve-icon
http://secunia.com/advisories/38563 cve-icon cve-icon
http://secunia.com/advisories/38640 cve-icon cve-icon
http://secunia.com/advisories/38658 cve-icon cve-icon
http://secunia.com/advisories/38712 cve-icon cve-icon
http://secunia.com/advisories/38915 cve-icon cve-icon
http://secunia.com/advisories/39509 cve-icon cve-icon
http://www.debian.org/security/2010/dsa-2038 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:041 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:085 cve-icon cve-icon
http://www.osvdb.org/62440 cve-icon cve-icon
http://www.securityfocus.com/bid/38294 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-902-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0413 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0914 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/1020 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=565792 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/56394 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-0423 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17554 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9842 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2010-0115.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-0423 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-02-24T18:00:00

Updated: 2024-08-07T00:45:12.274Z

Reserved: 2010-01-27T00:00:00

Link: CVE-2010-0423

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-02-24T18:30:00.530

Modified: 2024-11-21T01:12:11.270

Link: CVE-2010-0423

cve-icon Redhat

Severity : Low

Publid Date: 2010-02-18T00:00:00Z

Links: CVE-2010-0423 - Bugzilla