BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.
[ { "source": "https://github.com/bitlbee/bitlbee/commit/701ab8129ba9ea64f569daedca9a8603abad740f", "signature_version": "v1", "target": { "file": "protocols/bee_ft.c", "function": "imcb_file_send_start" }, "digest": { "length": 285.0, "function_hash": "200091833146978092335437910148232884039" }, "deprecated": false, "signature_type": "Function", "id": "CVE-2016-10189-496038f2" }, { "source": "https://github.com/bitlbee/bitlbee/commit/701ab8129ba9ea64f569daedca9a8603abad740f", "signature_version": "v1", "target": { "file": "protocols/bee_ft.c" }, "digest": { "line_hashes": [ "31214447550493281204817866590060204183", "210350765956590592246008159040789573546", "201206104002082530852136588434309667200", "134750621041171994627188307491181361821" ], "threshold": 0.9 }, "deprecated": false, "signature_type": "Line", "id": "CVE-2016-10189-f15d11ca" } ]