LWN.net Logo

pidgin: denial of service

Package(s):pidgin CVE #(s):CVE-2010-2528
Created:July 27, 2010 Updated:August 30, 2010
Description: From the Red Hat bugzilla:

Mark Doliner, upstream pidgin/libpurple developer, discovered a NULL pointer dereference flaw in the way libpurple handled certain malformed X-Status messages in ICQ/Oscar protocol. This flaw could allow remote attacker to crash the victim's instant messenger application using libpurple such as pidgin.

Alerts:
Slackware SSA:2010-240-05 2010-08-30
Pardus 2010-116 2010-08-12
Mandriva MDVSA-2010:148 2010-08-12
Fedora FEDORA-2010-11315 2010-07-23
Fedora FEDORA-2010-11321 2010-07-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds