CVE-2009-3085

CVSS 5.0 - MEDIUM
Description

The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images.

Affected Products
37
Vendor Product Version
pidgin libpurple All versions
pidgin pidgin All versions
pidgin pidgin 2.0.0
pidgin pidgin 2.0.1
pidgin pidgin 2.0.2
pidgin pidgin 2.0.2
pidgin pidgin 2.1.0
pidgin pidgin 2.1.1
pidgin pidgin 2.2.0
pidgin pidgin 2.2.1
pidgin pidgin 2.2.2
pidgin pidgin 2.3.0
pidgin pidgin 2.3.1
pidgin pidgin 2.4.0
pidgin pidgin 2.4.0
pidgin pidgin 2.4.1
pidgin pidgin 2.4.1
pidgin pidgin 2.4.2
pidgin pidgin 2.4.2
pidgin pidgin 2.4.3
pidgin pidgin 2.4.3
pidgin pidgin 2.5.0
pidgin pidgin 2.5.0
pidgin pidgin 2.5.1
pidgin pidgin 2.5.2
pidgin pidgin 2.5.2
pidgin pidgin 2.5.3
pidgin pidgin 2.5.3
pidgin pidgin 2.5.4
pidgin pidgin 2.5.4
pidgin pidgin 2.5.5
pidgin pidgin 2.5.5
pidgin pidgin 2.5.6
pidgin pidgin 2.5.7
pidgin pidgin 2.5.8
pidgin pidgin 2.5.9
pidgin pidgin 2.6.0
Weakness Types
NVD-CWE-Other
CVE Information
CVE ID:
CVE-2009-3085
Published:
2009-09-08
Modified:
2026-04-23
CVSS Score:
5.0
Severity:
MEDIUM
Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected Vendors
pidgin
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL