Jump to content

Advisories MDVSA-2010:085: pidgin


paul
 Share

Recommended Posts

Security vulnerabilities has been identified and fixed in pidgin:

 

The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium

before 1.3.7 allows remote attackers to cause a denial of service

(application crash) via crafted contact-list data for (1) ICQ and

possibly (2) AIM, as demonstrated by the SIM IM client (CVE-2009-3615).

 

Directory traversal vulnerability in slp.c in the MSN protocol

plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows

remote attackers to read arbitrary files via a .. (dot dot) in an

application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request,

a related issue to CVE-2004-0122. NOTE: it could be argued that

this is resultant from a vulnerability in which an emoticon download

request is processed even without a preceding text/x-mms-emoticon

message that announced availability of the emoticon (CVE-2010-0013).

 

Directory traversal vulnerability in slp.c in the MSN protocol

plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows

remote attackers to read arbitrary files via a .. (dot dot) in an

application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request,

a related issue to CVE-2004-0122. NOTE: it could be argued that

this is resultant from a vulnerability in which an emoticon download

request is processed even without a preceding text/x-mms-emoticon

message that announced availability of the emoticon (CVE-2010-0013).

 

Certain malformed SLP messages can trigger a crash because the MSN

protocol plugin fails to check that all pieces of the message are

set correctly (CVE-2010-0277).

 

In a user in a multi-user chat room has a nickname containing '

'

then libpurple ends up having two users with username ' ' in the room,

and Finch crashes in this situation. We do not believe there is a

possibility of remote code execution (CVE-2010-0420).

 

oCERT notified us about a problem in Pidgin, where a large amount of

processing time will be used when inserting many smileys into an IM

or chat window. This should not cause a crash, but Pidgin can become

unusable slow (CVE-2010-0423).

 

Packages for 2009.0 are provided due to the Extended Maintenance

Program.

 

This update provides pidgin 2.6.6, which is not vulnerable to these

issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...