CVE-2008-2927

CVSS 6.8 - MEDIUM
Description

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

Affected Products
25
Vendor Product Version
pidgin pidgin All versions
pidgin pidgin 2.0.0
pidgin pidgin 2.0.1
pidgin pidgin 2.0.2
pidgin pidgin 2.1.0
pidgin pidgin 2.1.1
pidgin pidgin 2.2.0
pidgin pidgin 2.2.1
pidgin pidgin 2.2.2
pidgin pidgin 2.3.0
pidgin pidgin 2.3.1
pidgin pidgin 2.4.0
pidgin pidgin 2.4.1
adium adium All versions
adium adium 1.0
adium adium 1.0.1
adium adium 1.0.2
adium adium 1.0.3
adium adium 1.0.4
adium adium 1.0.5
adium adium 1.1
adium adium 1.1.1
adium adium 1.1.2
adium adium 1.1.3
adium adium 1.1.4
Weakness Types
CWE-189
CVE Information
CVE ID:
CVE-2008-2927
Published:
2008-07-07
Modified:
2026-04-23
CVSS Score:
6.8
Severity:
MEDIUM
Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected Vendors
pidgin adium
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL