Critical severity9.8NVD Advisory· Published Apr 12, 2016· Updated Jun 17, 2026
CVE-2015-8833
CVE-2015-8833
Description
Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:cypherpunks:pidgin-otr:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cypherpunks:pidgin-otr:*:*:*:*:*:*:*:*range: <=4.0.1
- (no CPE)range: <4.0.2
- osv-coords5 versionspkg:rpm/opensuse/pidgin-otr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pidgin-otr&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/pidgin-otr&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/pidgin-otr&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012pkg:rpm/suse/pidgin-otr&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1
< 4.0.2-1.5+ 4 more
- (no CPE)range: < 4.0.2-1.5
- (no CPE)range: < 4.0.0-8.1
- (no CPE)range: < 4.0.0-8.1
- (no CPE)range: < 4.0.0-8.1
- (no CPE)range: < 4.0.0-8.1
Patches
Vulnerability mechanics
References
12- lists.opensuse.org/opensuse-security-announce/2016-03/msg00095.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-03/msg00109.htmlnvd
- www.debian.org/security/2016/dsa-3528nvd
- www.openwall.com/lists/oss-security/2016/03/09/13nvd
- www.openwall.com/lists/oss-security/2016/03/09/8nvd
- www.securityfocus.com/bid/84295nvd
- blog.fuzzing-project.org/39-Heap-use-after-free-in-Pidgin-OTR-plugin-CVE-2015-8833.htmlnvd
- bugs.otr.im/issues/128nvd
- bugs.otr.im/issues/88nvd
- bugs.otr.im/projects/pidgin-otr/repository/revisions/aaf551b9dd5cbba8c4abaa3d4dc7ead860efef94nvd
- lists.cypherpunks.ca/pipermail/otr-users/2016-March/002582.htmlnvd
- security.gentoo.org/glsa/201701-10nvd
News mentions
0No linked articles in our index yet.