CVE-2019-25544
NixOS vulnerability analysis and mitigation

Overview

CVE-2019-25544 is a Denial of Service (DoS) vulnerability in Pidgin 2.13.0 that allows a local attacker to crash the application by supplying an excessively long username string (approximately 1000 characters) during account creation. The crash is triggered when the user subsequently attempts to join a chat, rendering the application unavailable. It was publicly disclosed in March 2026 and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is rooted in improper validation of the quantity/length of user-supplied input in the username field during account creation (CWE-1284: Improper Validation of Specified Quantity in Input; CWE-807: Reliance on Untrusted Inputs in a Security Decision). An attacker with local access can enter a ~1000-character string in the username field; when the application subsequently processes this input upon joining a chat, it triggers a crash — likely due to a buffer overflow or unchecked string operation. A proof-of-concept exploit is publicly listed on Exploit-DB (Exploit-DB). Reproduction attempts against Pidgin 2.14.4 and 2.10.11-9.el7 were unsuccessful, suggesting the issue may be specific to version 2.13.0 or earlier (Red Hat Bugzilla).

Impact

Successful exploitation results in a crash of the Pidgin instant messaging application, causing a local denial of service. The impact is limited to availability — there is no evidence of confidentiality or integrity compromise. The scope is confined to the affected user's session, with no known potential for lateral movement or privilege escalation (Red Hat Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Local Access: Obtain local access to a system running Pidgin 2.13.0.
  2. Account Creation: Open Pidgin and navigate to the account creation dialog (Accounts > Manage Accounts > Add).
  3. Malformed Input: Enter an excessively long username string of approximately 1000 characters in the username field.
  4. Trigger Crash: Save the account and attempt to join a chat using the newly created account. The application will crash due to improper handling of the oversized input, resulting in a denial of service (Exploit-DB, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected Pidgin crash logs or core dump files generated after account creation with an unusually long username.
  • File System: Presence of core dump files (e.g., core.*) in the Pidgin working directory or user home directory following a crash event.
  • Process: Abrupt termination of the pidgin process without user-initiated exit, particularly after account creation or chat join attempts.

Mitigation and workarounds

Users should upgrade Pidgin beyond version 2.13.0; Pidgin 2.14.x appears unaffected based on reproduction testing (Red Hat Bugzilla). As a workaround, administrators can restrict local user access to Pidgin account creation functionality or implement input length validation policies. Red Hat has noted that RHEL-7 and RHEL-8 ship Pidgin versions at or below 2.13.0 and may be affected, while Fedora 42–45 and EPEL-9 ship Pidgin 2.14.x and are likely not affected (Red Hat Bugzilla).

Community reactions

Red Hat's Product Security team filed a bug report (BZ#2449948) and is tracking the issue, though no patch has been formally closed as of the last update. A Red Hat engineer noted difficulty reproducing the crash on newer Pidgin versions and requested a correct reproducer, suggesting the vulnerability's scope may be narrower than initially described (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary has been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management