CVE-2013-6487

high
Published 2014-02-06 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a large Content-Length value, which triggers a buffer overflow.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-6487

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.pidgin.im/news/security/?id=82

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://hg.pidgin.im/pidgin/main/rev/ec15aa187aa0

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:1.11.3-1
debian debianbullseyefixed1:1.11.3-1
debian debianforkyfixed1:1.11.3-1
debian debiansidfixed1:1.11.3-1
debian debiantrixiefixed1:1.11.3-1

Application impact

VendorProductVersionsFixed
pidginpidgin{"endIncluding":"2.10.7"}
pidginpidgin2.0.0
pidginpidgin2.0.1
pidginpidgin2.0.2
pidginpidgin2.1.0
pidginpidgin2.1.1
pidginpidgin2.10.0
pidginpidgin2.10.1
pidginpidgin2.10.2
pidginpidgin2.10.3
pidginpidgin2.10.4
pidginpidgin2.10.5
pidginpidgin2.10.6

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.