Cisco Talos is announcing the discovery and patching of another three 3 CVE vulnerabilities in Pidgin. The first vulnerability (CVE-2014-3697) is in the routines Pidgen uses to handle smiley and theme packages in Windows. The next vulnerability exists in the way Mxit Emoticons are handled. An attacker who can control the contents of a Novell protocol message can cause an out of memory exception by specifying an overly large size value for a memory allocation operation. An attack requires the ability to spoof mxit messages from the mxit mxit.com domain.”]
Source: https://blog.talosintelligence.com/2014/11/talos-discovered-three-more.html

