Vulnerability Description
Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar archive of a smiley theme.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pidgin | Pidgin | <= 2.10.9 |
Related Weaknesses (CWE)
References
- http://hg.pidgin.im/pidgin/main/rev/68b8eb10977fPatch
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00037.html
- http://pidgin.im/news/security/?id=89PatchVendor Advisory
- http://hg.pidgin.im/pidgin/main/rev/68b8eb10977fPatch
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00037.html
- http://pidgin.im/news/security/?id=89PatchVendor Advisory
FAQ
What is CVE-2014-3697?
CVE-2014-3697 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar arc...
How severe is CVE-2014-3697?
CVE-2014-3697 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3697?
Check the references section above for vendor advisories and patch information. Affected products include: Pidgin Pidgin.