VYPR
Unrated severityNVD Advisory· Published Feb 6, 2014· Updated Apr 29, 2026

CVE-2012-6152

CVE-2012-6152

Description

A flaw in Pidgin's Yahoo! protocol plugin allows remote attackers to crash the application via crafted UTF-8 byte sequences.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A flaw in Pidgin's Yahoo! protocol plugin allows remote attackers to crash the application via crafted UTF-8 byte sequences.

Vulnerability

The Yahoo! protocol plugin in libpurple in Pidgin before version 2.10.8 does not properly validate UTF-8 encoded data. This allows a remote attacker to send specially crafted byte sequences that cause a denial of service (application crash). Affected versions are all Pidgin earlier than 2.10.8 [1][2].

Exploitation

An attacker does not need authentication; they only need to be able to send a Yahoo! protocol message containing malformed UTF-8 data to a user running a vulnerable Pidgin instance. The attacker can be a remote Yahoo! user or potentially a man-in-the-middle [1][2].

Impact

Successful exploitation causes the Pidgin application to crash, resulting in a denial of service. No code execution is reported; the impact is limited to availability [1][2].

Mitigation

The vulnerability is fixed in Pidgin version 2.10.8 and later. Users should upgrade to at least version 2.10.8. Red Hat and Ubuntu have released security updates for their distributions [1][2].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

54
  • cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*+ 53 more
    • cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*range: <=2.10.7
    • cpe:2.3:a:pidgin:pidgin:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.4:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.5:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.10.6:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.5.9:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.10:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.11:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.5:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.6:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.7:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.8:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.7.9:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pidgin:pidgin:2.9.0:*:*:*:*:*:*:*
    • (no CPE)range: <2.10.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.