[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:230 -- Mandriva pidgin

ID: oval:org.secpod.oval:def:300584Date: (C)2012-01-07   (M)2024-01-29
Class: PATCHFamily: unix




Security vulnerabilities has been identified and fixed in pidgin: The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service by sending multiple crafted SLP messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376 . Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service via a link in a Yahoo IM protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the require TLS/SSL preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions . libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service via a TOPIC message that lacks a topic string . The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client . The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service via a handwritten message, related to an uninitialized variable and the incorrect UTF16-LE charset name . The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service via XHTML-IM content with cid: images . This update provides pidgin 2.6.2, which is not vulnerable to these issues.

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2009.1
Product:
pidgin
Reference:
MDVSA-2009:230
CVE-2009-3085
CVE-2009-3084
CVE-2009-3083
CVE-2009-2703
CVE-2009-3026
CVE-2009-3025
CVE-2009-2694
CVE    7
CVE-2009-3025
CVE-2009-3026
CVE-2009-2694
CVE-2009-3084
...
CPE    2
cpe:/o:mandriva:linux:2009.0
cpe:/o:mandriva:linux:2009.1

© SecPod Technologies