CVE-2013-0274 on Ubuntu 12.04 LTS (precise) - medium.
Description:
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.