pidgin: denial of service
| Package(s): | pidgin |
CVE #(s): | CVE-2011-1091
|
| Created: | March 14, 2011 |
Updated: | November 10, 2011 |
| Description: |
From the Red Hat bugzilla:
Multiple NULL pointer dereference flaws were found in the way Yahoo protocol plug-in of the Pidgin instant messaging client handled malformed YMSG packets (SMS messages and notification packets). A remote, authenticated user could use this flaw to cause denial of service (Pidgin crash) via specially-crafted notification message. The SMS messages handling issue is exploitable only via specially-crafted SMS message, sent from remote, malicious Yahoo server.
|
| Alerts: |
|