LWN.net Logo

pidgin: denial of service

Package(s):pidgin CVE #(s):CVE-2009-3025 CVE-2009-3084
Created:December 7, 2009 Updated:January 13, 2010
Description:

From the Mandriva advisory:

Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM (CVE-2009-3025)

The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect UTF16-LE charset name (CVE-2009-3084).

Alerts:
SuSE SUSE-SR:2009:020 2010-01-12
Mandriva MDVSA-2009:321 2009-12-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds