Pidgin Security Advisory
| Title | NULL pointer dereference parsing OIM data in MSN |
|---|---|
| Date | 2014-01-28 |
| CVE Name | CVE-2013-6482 |
| Discovered By | Fabian Yamaguchi and Christian Wressnegger of the University of Goettingen |
| Description | A malicious server or man-in-the-middle could send us a specially-crafted XML response that results in a NULL pointer dereference. |
| Fixed in Revision | ef836278304b |
| Fixed in Version | 2.10.8 |
| Fix | Check for NULL before calling atoi(). |



