CVE-2013-0274: Pidgin

Low severity, CVSS 2.9. EPSS: 1.4% chance of exploitation in the next 30 days.

upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.

Affected products

  • Pidgin Pidgin: up to and including 2.10.6; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.1.0 only; version 2.1.1 only; …

Published 2013-02-16. Last modified 2026-06-16.