
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25544 is a Denial of Service (DoS) vulnerability in Pidgin 2.13.0 that allows a local attacker to crash the application by supplying an excessively long username string (approximately 1000 characters) during account creation. The crash is triggered when the user subsequently attempts to join a chat, rendering the application unavailable. It was publicly disclosed in March 2026 and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The vulnerability is rooted in improper validation of the quantity/length of user-supplied input in the username field during account creation (CWE-1284: Improper Validation of Specified Quantity in Input; CWE-807: Reliance on Untrusted Inputs in a Security Decision). An attacker with local access can enter a ~1000-character string in the username field; when the application subsequently processes this input upon joining a chat, it triggers a crash — likely due to a buffer overflow or unchecked string operation. A proof-of-concept exploit is publicly listed on Exploit-DB (Exploit-DB). Reproduction attempts against Pidgin 2.14.4 and 2.10.11-9.el7 were unsuccessful, suggesting the issue may be specific to version 2.13.0 or earlier (Red Hat Bugzilla).
Successful exploitation results in a crash of the Pidgin instant messaging application, causing a local denial of service. The impact is limited to availability — there is no evidence of confidentiality or integrity compromise. The scope is confined to the affected user's session, with no known potential for lateral movement or privilege escalation (Red Hat Advisory, Red Hat Bugzilla).
core.*) in the Pidgin working directory or user home directory following a crash event.pidgin process without user-initiated exit, particularly after account creation or chat join attempts.Users should upgrade Pidgin beyond version 2.13.0; Pidgin 2.14.x appears unaffected based on reproduction testing (Red Hat Bugzilla). As a workaround, administrators can restrict local user access to Pidgin account creation functionality or implement input length validation policies. Red Hat has noted that RHEL-7 and RHEL-8 ship Pidgin versions at or below 2.13.0 and may be affected, while Fedora 42–45 and EPEL-9 ship Pidgin 2.14.x and are likely not affected (Red Hat Bugzilla).
Red Hat's Product Security team filed a bug report (BZ#2449948) and is tracking the issue, though no patch has been formally closed as of the last update. A Red Hat engineer noted difficulty reproducing the crash on newer Pidgin versions and requested a correct reproducer, suggesting the vulnerability's scope may be narrower than initially described (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."