|
|
| |
|
| |
pidgin: two denial of service vulnerabilities
| Package(s): | pidgin |
CVE #(s): | CVE-2011-4939
CVE-2012-1178
|
| Created: | March 16, 2012 |
Updated: | March 26, 2012 |
| Description: |
From the Mandriva advisory:
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin
before 2.10.2 allows remote attackers to cause a denial of service
(NULL pointer dereference and application crash) by changing a nickname
while in an XMPP chat room (CVE-2011-4939).
The msn_oim_report_to_user function in oim.c in the MSN protocol
plugin in libpurple in Pidgin before 2.10.2 allows remote servers to
cause a denial of service (application crash) via an OIM message that
lacks UTF-8 encoding (CVE-2012-1178). |
| Alerts: |
|
( Log in to post comments)
|
|
|