Adium vulnerable to remote code execution via libpurple

Posted by erythronium23 on Mar 21

Adium is a popular instant messaging client for MacOS (OSX) that
incorporates libpurple. The current release (1.5.10.2) is vulnerable
to CVE-2017-2640 in libpurple, which permits execution of arbitrary
code on the client.

The Adium team has been aware of the vulnerability since at least
March 15, but has not released an advisory to its users, for reasons
unknown.

A post to the official developer’s mailing list, which included
vulnerability…

Leave a Reply