CVE-2012-2369: Cypherpunks Pidgin-Otr

High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.

Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.

Affected products

Published 2012-05-23. Last modified 2026-06-16.