LWN.net Logo

pidgin: multiple vulnerabilities

Package(s):pidgin CVE #(s):CVE-2009-2703 CVE-2009-3026 CVE-2009-3083 CVE-2009-3085
Created:September 21, 2009 Updated:January 18, 2010
Description: From the Red Hat advisory:

A NULL pointer dereference flaw was found in the way the Pidgin XMPP protocol plug-in processes IQ error responses when trying to fetch a custom smiley. A remote client could send a specially-crafted IQ error response that would crash Pidgin. (CVE-2009-3085)

A NULL pointer dereference flaw was found in the way the Pidgin IRC protocol plug-in handles IRC topics. A malicious IRC server could send a specially-crafted IRC TOPIC message, which once received by Pidgin, would lead to a denial of service (Pidgin crash). (CVE-2009-2703)

It was discovered that, when connecting to certain, very old Jabber servers via XMPP, Pidgin may ignore the "Require SSL/TLS" setting. In these situations, a non-encrypted connection is established rather than the connection failing, causing the user to believe they are using an encrypted connection when they are not, leading to sensitive information disclosure (session sniffing). (CVE-2009-3026)

A NULL pointer dereference flaw was found in the way the Pidgin MSN protocol plug-in handles improper MSNSLP invitations. A remote attacker could send a specially-crafted MSNSLP invitation request, which once accepted by a valid Pidgin user, would lead to a denial of service (Pidgin crash). (CVE-2009-3083)

Alerts:
Ubuntu USN-886-1 2010-01-18
SuSE SUSE-SR:2009:020 2010-01-12
Mandriva MDVSA-2009:321 2009-12-06
CentOS CESA-2009:1453 2009-09-22
Red Hat RHSA-2009:1453-01 2009-09-21
CentOS CESA-2009:1535 2009-10-29
Gentoo 200910-02 2009-10-22
Red Hat RHSA-2009:1535-01 2009-10-29
CentOS CESA-2009:1453 2009-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds