CVE-2014-3697

medium
Published 2014-10-29 · Modified 2026-05-06
CVSS v3
VIR risk
6.4

Description

Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar archive of a smiley theme.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
pidginpidgin{"endIncluding":"2.10.9"}
pidginpidgin2.10.0
pidginpidgin2.10.1
pidginpidgin2.10.2
pidginpidgin2.10.3
pidginpidgin2.10.4
pidginpidgin2.10.5
pidginpidgin2.10.6
pidginpidgin2.10.7
pidginpidgin2.10.8

References

CWEs

CWE-22

💬 Discuss CVE-2014-3697 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.