title: cve-2009-3615-00
date: 2009-10-16T00:00:00.000Z
cveNumber: cve-2009-3615
summary: ICQ and maybe AIM remote crash
discoveredBy: nightwing666 in ticket #10481
fixedInRelease: 2.6.3
type: security
layout: cve
hidden: true
### Description
A specially crafted message can trigger an incorrect memory access in the oscar
protocol plugin which can lead to a crash. This happens when the SIM IM client
attempts to send contacts to a libpurple user.
### Mitigation
Check for the correct number of fields before attempting to dereference memory.