Blog | G5 Cyber Security

VRT-2013-1004 (CVE-2013-6490): Buffer overflow in SIMPLE header parsing

Sourcefire Vulnerability Report VRT-2013-1004: Buffer overflow in SIMPLE header parsing. Remote code execution vulnerability exists in Pidgin’s implementation of SIP/SIMPLE message handling. An attacker who can control the Content-Length of a message can cause an allocation to return NULL which can later be used to write into the lowest page of memory. The vulnerability is described as a vulnerability that could be exploited by a remote code execution attack on Pidgen’s SIP preprocessor.”]

Source: https://blog.talosintelligence.com/2014/01/vrt-2013-1004-cve-2013-6490-buffer.html

Exit mobile version