Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pidgin‘Libpurple’Cipher API 信息泄露漏洞
Vulnerability Description
Pidgin是一款跨平台的实时通信客户端,它支持多个常用的实时通信协议,用户可用同一个软件登录不同的实时通信服务。 Pidgin 2.7.10之前版本中的libpurple中的Cipher AP中的cipher.c中存在信息泄露漏洞,该漏洞源于加密密钥保留在进程内存中。本地攻击者可利用该漏洞通过读取核心文件或内存内容的其他代表,进而获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A