Back to Database
Status published
Critical
CVE-2011-3185
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote...
Vulnerability Description
gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3185
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69342
- http://www.openwall.com/lists/oss-security/2011/08/22/10
- http://www.securityfocus.com/archive/1/519391/100/0/threaded
- http://developer.pidgin.im/viewmtn/revision/info/5749f9193063800d27bef75c2388f6f9cc2f7f37
- http://pidgin.im/news/security/?id=55
- http://secunia.com/advisories/45663
- http://www.openwall.com/lists/oss-security/2011/08/22/7
- http://www.openwall.com/lists/oss-security/2011/08/22/
- http://www.openwall.com/lists/oss-security/2011/08/22/12
- http://www.insomniasec.com/advisories/ISVA-110822.1.htm
- http://developer.pidgin.im/viewmtn/revision/diff/29484df15413fe3bbd21bbfcef26a55362055a81/with/5749f9193063800d27bef75c2388f6f9cc2f7f37/pidgin/gtkutils.c
- http://www.securityfocus.com/bid/49268
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18324
- http://securitytracker.com/id?1025961
More from pidgin
View All →CVE-2022-26491
An issue was discovered in Pidgin before 2.14.9. A remote...
Medium
5.9
CVE-2016-2379
The Mxit protocol uses weak encryption when encrypting user passwords,...
High
8.8
CVE-2014-3698
The jabber_idn_validate function in jutil.c in the Jabber protocol plugin...
Medium
5
CVE-2014-3697
Absolute path traversal vulnerability in the untar_block function in win32/untar.c...
Medium
6.4
CVE-2014-3696
nmevent.c in the Novell GroupWise protocol plugin in libpurple in...
Medium
5
Affected Vendor
pidgin
View all reports →Affected Software
pidgin
Vulnerable Versions:
0, 2.0.0, 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7, 2.5.8, 2.5.9, 2.6.0, 2.6.1, 2.6.2, 2.6.4, 2.6.5, 2.6.6, 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7, 2.7.8, 2.7.9, 2.7.10, 2.7.11, 2.8.0
Timeline
Official Publish:
August 29th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.