Unrated severityNVD Advisory· Published Oct 29, 2014· Updated May 6, 2026
CVE-2014-3698
CVE-2014-3698
Description
The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message.
Affected products
10cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*range: <=2.10.9
- cpe:2.3:a:pidgin:pidgin:2.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.1:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.2:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.3:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.4:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.5:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.6:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.7:*:*:*:*:*:*:*
- cpe:2.3:a:pidgin:pidgin:2.10.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- hg.pidgin.im/pidgin/main/rev/ea46ab68f0dcnvdPatch
- pidgin.im/news/security/nvdPatchVendor Advisory
- lists.opensuse.org/opensuse-updates/2014-11/msg00023.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-11/msg00037.htmlnvd
- secunia.com/advisories/60741nvd
- secunia.com/advisories/61968nvd
- www.debian.org/security/2014/dsa-3055nvd
- www.ubuntu.com/usn/USN-2390-1nvd
- access.redhat.com/errata/RHSA-2017:1854nvd
News mentions
0No linked articles in our index yet.