title: cve-2016-2372-00
date: 2016-06-21T00:00:00.000Z
cveNumber: cve-2016-2372
talosReportID: talos-2016-0140
summary: Pidgin MXIT File Transfer Length Memory Disclosure Vulnerability
discoveredBy: Yves Younan of Cisco Talos
fixedInRelease: 2.11.0
type: security
layout: cve
hidden: true
### Description
A malicious user, server, or man-in-the-middle could trigger a crash or
unexpected writing of data from memory to file.
### Mitigation
Various changes to the chunk decoding.