bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.
[
{
"source": "https://github.com/bitlbee/bitlbee/commit/30d598ce7cd3f136ee9d7097f39fa9818a272441",
"target": {
"file": "protocols/purple/ft.c"
},
"digest": {
"line_hashes": [
"129746416437449350037320385203030176865",
"54330094966721710425087619277153961551",
"304472804705248427345056028139318669522",
"339748322777452188179812311987678535759"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2017-5668-136ab83a",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://github.com/bitlbee/bitlbee/commit/30d598ce7cd3f136ee9d7097f39fa9818a272441",
"target": {
"function": "prplcb_xfer_new_send_cb",
"file": "protocols/purple/ft.c"
},
"digest": {
"function_hash": "171639359075992639380024064189635207014",
"length": 594.0
},
"deprecated": false,
"id": "CVE-2017-5668-d1255de3",
"signature_version": "v1",
"signature_type": "Function"
}
]