pidgin/nest
Clone
Summary
Browse
Changes
Graph
Update the ChangeLog for 2.14.13
default
tip
3 days ago, Gary Kramlich
14cc352bb7a2
Update the ChangeLog for 2.14.13
Testing Done:
Ran the site locally.
Reviewed at https://reviews.imfreedom.org/r/3046/
---
title: cve-2013-6481-00
date: 2014-01-28T00:00:00.000Z
cveNumber: cve-2013-6481
summary: Remote crash reading Yahoo! P2P message
discoveredBy: Daniel Atallah
fixedInRelease: 2.10.8
type: security
layout: cve
hidden: true
---
### Description
The Yahoo! protocol plugin failed to validate a length field before trying to
read from a buffer, which could result in reading past the end of the buffer
which could cause a crash.
### Mitigation
Check that the length is within range.