VYPR
High severity7.5NVD Advisory· Published Jan 9, 2010· Updated Apr 23, 2026

CVE-2010-0013

CVE-2010-0013

Description

Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.

Affected products

10
  • cpe:2.3:a:adium:adium:1.3.8:*:*:*:*:*:*:*
  • cpe:2.3:a:pidgin:pidgin:2.6.4:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
    Range: >=11.0,<=11.2
  • cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:*+ 1 more
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp2:*:*:-:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:-:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

24

News mentions

0

No linked articles in our index yet.