Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2956 to the following vulnerability: Memory leak in Pidgin 2.0.0, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via malformed XML documents. Proposed patch in CRISP Advisory 2007-01: http://crisp.cs.du.edu/crisp-files/pidgin-2.0.0-xmlnode-pool-leak.diff References: http://crisp.cs.du.edu/?q=ca2007-1 http://www.securityfocus.com/bid/29985 http://www.openwall.com/lists/oss-security/2008/06/27/3
Upstream disputes this as being a flaw: http://developer.pidgin.im/ticket/11470 Accordingly, it has not been fixed upstream.