LWN.net Logo

pidgin: remote code execution

Package(s):pidgin CVE #(s):CVE-2012-3374
Created:July 9, 2012 Updated:March 15, 2013
Description: From the Debian advisory:

Ulf Härnhammar found a buffer overflow in Pidgin, a multi protocol instant messaging client. The vulnerability can be exploited by an incoming message in the MXit protocol plugin. A remote attacker may cause a crash, and in some circumstances can lead to remote code execution.

Alerts:
Debian DSA-2509-1 2012-07-08
Ubuntu USN-1500-1 2012-07-09
Mageia MGASA-2012-0154 2012-07-10
Fedora FEDORA-2012-10287 2012-07-10
Mandriva MDVSA-2012:105 2012-07-12
Slackware SSA:2012-195-02 2012-07-14
Fedora FEDORA-2012-10294 2012-07-14
Red Hat RHSA-2012:1102-01 2012-07-19
CentOS CESA-2012:1102 2012-07-19
CentOS CESA-2012:1102 2012-07-19
SUSE SUSE-SU-2012:0890-1 2012-07-19
Oracle ELSA-2012-1102 2012-07-20
Scientific Linux SL-pidg-20120719 2012-07-19
Gentoo 201209-17 2012-09-27
Oracle ELSA-2013-0646 2013-03-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds