BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.
{ "vanir_signatures": [ { "signature_type": "Function", "target": { "function": "imcb_file_send_start", "file": "protocols/bee_ft.c" }, "source": "https://github.com/bitlbee/bitlbee/commit/701ab8129ba9ea64f569daedca9a8603abad740f", "id": "CVE-2016-10189-496038f2", "signature_version": "v1", "deprecated": false, "digest": { "function_hash": "200091833146978092335437910148232884039", "length": 285.0 } }, { "signature_type": "Line", "target": { "file": "protocols/bee_ft.c" }, "source": "https://github.com/bitlbee/bitlbee/commit/701ab8129ba9ea64f569daedca9a8603abad740f", "id": "CVE-2016-10189-f15d11ca", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "31214447550493281204817866590060204183", "210350765956590592246008159040789573546", "201206104002082530852136588434309667200", "134750621041171994627188307491181361821" ], "threshold": 0.9 } } ] }