CVE-2012-2369

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
23/05/2012
Last modified:
11/04/2025

Description

Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cypherpunks:pidgin-otr:*:*:*:*:*:*:*:* 3.2.0 (including)
cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*