← Vulnerability feed

Vulnerability record · CVE-2008-2927 · published 7 July 2008

CVE-2008-2927: Pidgin vulnerability

Pidgin · Pidgin

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

6.8 CVSS 2.0 Medium EPSS 4.3% · top 9.1% CWE-189 · CWE-189
6.8CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
62References
16 Jun 2026Last modified by NVD

Description

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240
http://secunia.com/advisories/30971 Vendor Advisory
http://secunia.com/advisories/31016 Vendor Advisory
http://secunia.com/advisories/31105 Vendor Advisory
http://secunia.com/advisories/31387 Vendor Advisory
http://secunia.com/advisories/31642 Vendor Advisory
http://secunia.com/advisories/32859
http://secunia.com/advisories/32861
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0246
http://www.debian.org/security/2008/dsa-1610
http://www.mandriva.com/security/advisories?name=MDVSA-2008:143
http://www.mandriva.com/security/advisories?name=MDVSA-2009:127
http://www.openwall.com/lists/oss-security/2008/07/03/6
http://www.openwall.com/lists/oss-security/2008/07/04/1
http://www.pidgin.im/news/security/?id=25
http://www.redhat.com/support/errata/RHSA-2008-0584.html
http://www.securityfocus.com/archive/1/493682
http://www.securityfocus.com/archive/1/495165/100/0/threaded
http://www.securityfocus.com/archive/1/495818/100/0/threaded
http://www.securityfocus.com/bid/29956
http://www.securitytracker.com/id?1020451
http://www.ubuntu.com/usn/USN-675-1
http://www.ubuntu.com/usn/USN-675-2
http://www.vupen.com/english/advisories/2008/2032/references Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-054
https://bugzilla.redhat.com/show_bug.cgi?id=453764
https://exchange.xforce.ibmcloud.com/vulnerabilities/44774
https://issues.rpath.com/browse/RPL-2647
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11695
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17972
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240
http://secunia.com/advisories/30971 Vendor Advisory
http://secunia.com/advisories/31016 Vendor Advisory
http://secunia.com/advisories/31105 Vendor Advisory
http://secunia.com/advisories/31387 Vendor Advisory
http://secunia.com/advisories/31642 Vendor Advisory
http://secunia.com/advisories/32859
http://secunia.com/advisories/32861

Track CVE-2008-2927 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-6490Pidgin memory buffer overflow vulnerabilityThe SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header,…EPSS 15%10.0CVE-2008-7190Adium vulnerabilityUnspecified vulnerability in Adium before 1.2 has unknown impact and attack vectors related to javascript: URLs, possibly cross-site scripting (XSS).EPSS 1.2%10.0CVE-2009-2694Adium vulnerabilityThe msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.…EPSS 20%9.8CVE-2016-1000030Suse linux enterprise server improper certificate validation vulnerabilityPidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_cr…EPSS 1.8%9.8CVE-2017-2640Pidgin out-of-bounds write vulnerabilityAn out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…EPSS 6.3%9.3CVE-2013-6486Pidgin improper input validation vulnerabilitygtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: UR…EPSS 3.8%9.3CVE-2011-3185Pidgin improper input validation vulnerabilitygtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.EPSS 4.8%9.3CVE-2009-1376Pidgin vulnerabilityMultiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2008-2927), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.