CVE-2009-1376

Pidgin < 2.5.6 - Remote Code Execution via Malformed SLP Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1376.

AI-analyzed exploit summary This is a functional exploit for CVE-2009-1376, targeting a memory corruption vulnerability in Pidgin's MSN protocol handling. It crafts a malicious MsnSlp packet to overwrite stack memory and execute arbitrary shellcode (e.g., launching calc.exe).

Description

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.

Exploits (1)

exploitdb WORKING POC
remotewindows
https://www.exploit-db.com/exploits/9615

This is a functional exploit for CVE-2009-1376, targeting a memory corruption vulnerability in Pidgin's MSN protocol handling. It crafts a malicious MsnSlp packet to overwrite stack memory and execute arbitrary shellcode (e.g., launching calc.exe).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pidgin <= 2.5.8 (libmsn)
Auth required
Prerequisites: Valid MSN credentials for attacker and target · Target must accept the attacker's contact invitation · Java MSN Messenger library (jml)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (26)

Core 26
Core References
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:140
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:173
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10476
Vendor Advisory x_refsource_confirm
http://www.pidgin.im/news/security/?id=32
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1060.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-781-2
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2009-1059.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35067
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35329
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-781-1
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18432
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37071
Third Party Advisory vendor-advisory x_refsource_debian
http://debian.org/security/2009/dsa-1805
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35294
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35188
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35194
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35202
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50680
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35215
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1396
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35330

Scores

EPSS 0.1329
EPSS Percentile 95.9%

Details

CWE
CWE-189
Status published
Products (9)
pidgin/pidgin 2.4.0 32_bit
pidgin/pidgin 2.4.1 32_bit
pidgin/pidgin 2.4.2 32_bit
pidgin/pidgin 2.4.3 32_bit
pidgin/pidgin 2.5.0 32_bit
pidgin/pidgin 2.5.2 32_bit
pidgin/pidgin 2.5.3 32_bit
pidgin/pidgin 2.5.4 32_bit
pidgin/pidgin < 2.5.5
Published May 26, 2009
Tracked Since Feb 18, 2026