bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.
{ "vanir_signatures": [ { "id": "CVE-2017-5668-136ab83a", "digest": { "line_hashes": [ "129746416437449350037320385203030176865", "54330094966721710425087619277153961551", "304472804705248427345056028139318669522", "339748322777452188179812311987678535759" ], "threshold": 0.9 }, "signature_version": "v1", "deprecated": false, "target": { "file": "protocols/purple/ft.c" }, "signature_type": "Line", "source": "https://github.com/bitlbee/bitlbee/commit/30d598ce7cd3f136ee9d7097f39fa9818a272441" }, { "id": "CVE-2017-5668-d1255de3", "digest": { "length": 594.0, "function_hash": "171639359075992639380024064189635207014" }, "signature_version": "v1", "deprecated": false, "target": { "file": "protocols/purple/ft.c", "function": "prplcb_xfer_new_send_cb" }, "signature_type": "Function", "source": "https://github.com/bitlbee/bitlbee/commit/30d598ce7cd3f136ee9d7097f39fa9818a272441" } ] }