|
|
Log in / Subscribe / Register

pidgin: data corruption

Package(s):pidgin CVE #(s):CVE-2009-1374 CVE-2009-1375
Created:May 22, 2009 Updated:December 7, 2009
Description: From the Red Hat advisory:

A denial of service flaw was found in Pidgin's QQ protocol decryption handler. When the QQ protocol decrypts packet information, heap data can be overwritten, possibly causing Pidgin to crash. (CVE-2009-1374)

A flaw was found in the way Pidgin's PurpleCircBuffer object is expanded. If the buffer is full when more data arrives, the data stored in this buffer becomes corrupted. This corrupted data could result in confusing or misleading data being presented to the user, or possibly crash Pidgin. (CVE-2009-1375)

Alerts:
Mandriva MDVSA-2009:321 pidgin 2009-12-06
SuSE SUSE-SR:2009:013 memcached, libtiff/libtiff3, nagios, libsndfile, gaim/finch, open-, strong, freeswan, libapr-util1, websphere-as_ce, libxml2 2009-08-11
Mandriva MDVSA-2009:173 pidgin 2009-07-29
Mandriva MDVSA-2009:147 pidgin 2009-06-30
Ubuntu USN-781-1 pidgin 2009-06-03
Fedora FEDORA-2009-5583 pidgin 2009-05-28
Fedora FEDORA-2009-5597 pidgin 2009-05-28
Fedora FEDORA-2009-5552 pidgin 2009-05-28
Slackware SSA:2009-146-01 pidgin 2009-05-27
Gentoo 200905-07 pidgin 2009-05-25
Debian DSA-1805-1 pidgin 2009-05-22
CentOS CESA-2009:1060 pidgin 2009-05-22
Red Hat RHSA-2009:1060-02 pidgin 2009-05-22

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds