CVE-2010-3088

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/10/2010
Last modified:
11/04/2025

Description

The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jianping_yu:pidgin-knotify:*:*:*:*:*:*:*:* 0.2.1 (including)
cpe:2.3:a:jianping_yu:pidgin-knotify:0.1:*:*:*:*:*:*:*
cpe:2.3:a:jianping_yu:pidgin-knotify:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:jianping_yu:pidgin-knotify:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*