Low severity3.7NVD Advisory· Published Jan 6, 2017· Updated Jun 17, 2026
CVE-2016-4323
CVE-2016-4323
Description
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*range: <=2.10.12
- (no CPE)
- (no CPE)range: 2.10.11
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- www.pidgin.im/news/security/nvdPatchVendor Advisory
- www.talosintelligence.com/reports/TALOS-2016-0128/nvdExploitThird Party Advisory
- www.debian.org/security/2016/dsa-3620nvdThird Party Advisory
- www.ubuntu.com/usn/USN-3031-1nvdThird Party Advisory
- www.securityfocus.com/bid/91335nvd
- security.gentoo.org/glsa/201701-38nvd
News mentions
0No linked articles in our index yet.