|
|
| |
|
| |
pidgin: data corruption
| Package(s): | pidgin |
CVE #(s): | CVE-2009-1374
CVE-2009-1375
|
| Created: | May 22, 2009 |
Updated: | December 7, 2009 |
| Description: |
From the Red Hat advisory:
A denial of service flaw was found in Pidgin's QQ protocol decryption
handler. When the QQ protocol decrypts packet information, heap data can be
overwritten, possibly causing Pidgin to crash. (CVE-2009-1374)
A flaw was found in the way Pidgin's PurpleCircBuffer object is expanded.
If the buffer is full when more data arrives, the data stored in this
buffer becomes corrupted. This corrupted data could result in confusing or
misleading data being presented to the user, or possibly crash Pidgin.
(CVE-2009-1375)
|
| Alerts: |
|
( Log in to post comments)
|
|
|