hugo/content/about/security/advisories/cve-2009-3083-00.md

Fri, 30 Aug 2024 19:33:36 -0500

author
Gary Kramlich <grim@reaperworld.com>
date
Fri, 30 Aug 2024 19:33:36 -0500
changeset 543
4ab2b8637540
parent 402
91f916eba5fd
permissions
-rw-r--r--

Update the plugins page for the new process

This includes defining the process and providing a template for a new issue to
add new plugins. I did go through and audit `No IRC /WHO` so we had at least
one validated entry.

Testing Done:
Ran `npm run hugo:server` locally and verified the page worked and checked the new links.

Bugs closed: NEST-53

Reviewed at https://reviews.imfreedom.org/r/3450/

---
title: cve-2009-3083-00
date: 2009-09-03T00:00:00.000Z
cveNumber: cve-2009-3083
summary: MSN partial SLP invite crash
discoveredBy: blackstar in ticket #10159 and Elliott Sales de Andrade
fixedInRelease: 2.6.2
type: security
layout: cve
hidden: true
---

### Description

The MSN protocol plugin extracts some fields from an incoming SLP invite. If
some of these fields do not exist in the invite message then the protocol plugin
will attempt to dereference a NULL pointer and will crash.

### Mitigation

Check for NULL values and handle appropriately.

mercurial