CVE-2017-5668

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
14/03/2017
Last modified:
20/04/2025

Description

bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitlbee:bitlbee:*:*:*:*:*:*:*:* 3.4.2 (including)
cpe:2.3:a:bitlbee:bitlbee-libpurple:*:*:*:*:*:*:*:* 3.5 (including)