CVE-2012-2369: Cypherpunks Pidgin-Otr
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message.
Affected products
- Cypherpunks Pidgin-Otr: up to and including 3.2.0
Published 2012-05-23. Last modified 2026-06-16.