LWN.net Logo

pidgin: multiple vulnerabilities

Package(s):pidgin CVE #(s):CVE-2008-2955 CVE-2008-2957 CVE-2008-3532
Created:November 24, 2008 Updated:January 18, 2010
Description:

From the Ubuntu advisory:

It was discovered that Pidgin did not properly handle file transfers containing a long filename and special characters in the MSN protocol handler. A remote attacker could send a specially crafted filename in a file transfer request and cause Pidgin to crash, leading to a denial of service. (CVE-2008-2955)

It was discovered that Pidgin did not impose resource limitations in the UPnP service. A remote attacker could cause Pidgin to download arbitrary files and cause a denial of service from memory or disk space exhaustion. (CVE-2008-2957)

It was discovered that Pidgin did not validate SSL certificates when using a secure connection. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. This update alters Pidgin behaviour by asking users to confirm the validity of a certificate upon initial login. (CVE-2008-3532)

Alerts:
Ubuntu USN-886-1 2010-01-18
Mandriva MDVSA-2009:321 2009-12-06
Gentoo 200901-13 2009-01-20
Mandriva MDVSA-2009:025 2008-01-22
CentOS CESA-2008:1023 2008-12-15
Red Hat RHSA-2008:1023-01 2008-12-15
Ubuntu USN-675-1 2008-11-24

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds