Pidgin Security Advisory
| Title | ICQ X-Status denial of service |
|---|---|
| Date | 2010-07-21 |
| CVE Name | CVE-2010-2528 |
| Discovered By | Mark Doliner |
| Summary | libpurple clients can crash due to malformed X-Status messages |
| Description | Certain incorrectly formed X-Status messages can cause libpurple to attempt to dereference a NULL pointer, which triggers a crash. |
| Fixed in Revision | a56f371f289a |
| Fixed in Version | 2.7.2 |
| Fix | Improve the parsing of the X-Status message to be more robust |



