|
|
Subscribe / Log in / New account

pidgin: multiple vulnerabilities

Package(s):pidgin CVE #(s):CVE-2010-0277 CVE-2010-0420 CVE-2010-0423
Created:February 18, 2010 Updated:November 15, 2010
Description: From the Red Hat alert:

An input sanitization flaw was found in the way Pidgin's MSN protocol implementation handled MSNSLP invitations. A remote attacker could send a specially-crafted INVITE request that would cause a denial of service (memory corruption and Pidgin crash). (CVE-2010-0277)

A denial of service flaw was found in Finch's XMPP chat implementation, when using multi-user chat. If a Finch user in a multi-user chat session were to change their nickname to contain the HTML "br" element, it would cause Finch to crash. (CVE-2010-0420) Red Hat would like to thank Sadrul Habib Chowdhury of the Pidgin project for responsibly reporting the CVE-2010-0420 issue.

A denial of service flaw was found in the way Pidgin processed emoticon images. A remote attacker could flood the victim with emoticon images during mutual communication, leading to excessive CPU use. (CVE-2010-0423)

Alerts:
Debian DSA-2038-3 pidgin 2010-11-13
Debian DSA-2038-2 pidgin 2010-05-17
Mandriva MDVSA-2010:085 pidgin 2010-04-28
Debian DSA-2038-1 pidgin 2010-04-18
SuSE SUSE-SR:2010:006 2010-03-15
Slackware SSA:2010-069-01 pidgin 2010-03-11
Pardus 2010-34 pidgin 2010-02-25
CentOS CESA-2010:0115 pidgin 2010-02-20
Ubuntu USN-902-1 pidgin 2010-02-22
Fedora FEDORA-2010-1383 pidgin 2010-02-19
Fedora FEDORA-2010-1934 pidgin 2010-02-19
Mandriva MDVSA-2010:041 pidgin 2010-02-18
Red Hat RHSA-2010:0115-01 pidgin 2010-02-18
CentOS CESA-2010:0115 pidgin 2010-02-23
Fedora FEDORA-2010-1279 pidgin 2010-02-19

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds