|
|
Log in / Subscribe / Register

pidgin: multiple vulnerabilities

Package(s):pidgin CVE #(s):CVE-2013-0271 CVE-2013-0272 CVE-2013-0273 CVE-2013-0274
Created:February 14, 2013 Updated:March 21, 2013
Description:

From the Pidgin advisories:

CVE-2013-0271: The MXit protocol plugin saves an image to local disk using a filename that could potentially be partially specified by the IM server or by a remote user.

CVE-2013-0272: The code did not respect the size of the buffer when parsing HTTP headers, and a malicious server or man-in-the-middle could send specially crafted data that could overflow the buffer. This could lead to a crash or remote code execution.

CVE-2013-0273: libpurple failed to null-terminate user IDs that were longer than 4096 bytes. It's plausible that a malicious server could send one of these to us, which would lead to a crash.

CVE-2013-0274: libpurple failed to null-terminate some strings when parsing the response from a UPnP router. This could lead to a crash if a malicious user on your network responds with a specially crafted message.

Alerts:
Gentoo 201405-22 pidgin 2014-05-18
openSUSE openSUSE-SU-2013:0511-1 pidgin 2013-03-21
Scientific Linux SL-pidg-20130314 pidgin 2013-03-14
Oracle ELSA-2013-0646 pidgin 2013-03-14
CentOS CESA-2013:0646 pidgin 2013-03-14
Red Hat RHSA-2013:0646-01 pidgin 2013-03-14
Mandriva MDVSA-2013:025 pidgin 2013-03-14
openSUSE openSUSE-SU-2013:0405-1 pidgin 2013-03-07
openSUSE openSUSE-SU-2013:0407-1 pidgin 2013-03-07
SUSE SUSE-SU-2013:0388-1 pidgin 2013-03-04
Ubuntu USN-1746-1 pidgin 2013-02-25
Mageia MGASA-2013-0058 pidgin 2013-02-21
Slackware SSA:2013-044-01 pidgin 2013-02-13

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds