CVE-2016-1000030

unknown
Published — · Modified —
CVSS v3
CVSS v2
VIR risk

Description

Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-1000030

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-1000030.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed2.11.0-1
debian debianbullseyefixed2.11.0-1
debian debianforkyfixed2.11.0-1
debian debiansidfixed2.11.0-1
debian debiantrixiefixed2.11.0-1

References

Verify integrity in audit chain (admin only). AS-IS.