USN-902-1: Pidgin vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) USN-902-1: Pidgin vulnerabilities
# 1  
Old 02-22-2010
USN-902-1: Pidgin vulnerabilities

Referenced CVEs:
CVE-2010-0277, CVE-2010-0420, CVE-2010-0423


Description:
===========================================================Ubuntu Security Notice USN-902-1 February 22, 2010pidgin vulnerabilitiesCVE-2010-0277, CVE-2010-0420, CVE-2010-0423===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04Ubuntu 9.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: pidgin 1:2.4.1-1ubuntu2.9Ubuntu 8.10: pidgin 1:2.5.2-0ubuntu1.7Ubuntu 9.04: pidgin 1:2.5.5-1ubuntu8.6Ubuntu 9.10: pidgin 1:2.6.2-1ubuntu7.2After a standard system upgrade you need to restart Pidgin to effectthe necessary changes.Details follow:Fabian Yamaguchi discovered that Pidgin incorrectly validated all fields ofan incoming message in the MSN protocol handler. A remote attacker couldsend a specially crafted message and cause Pidgin to crash, leading to adenial of service. (CVE-2010-0277)Sadrul Habib Chowdhury discovered that Pidgin incorrectly handled certainnicknames in Finch group chat rooms. A remote attacker could use aspecially crafted nickname and cause Pidgin to crash, leading to a denialof service. (CVE-2010-0420)Antti Hayrynen discovered that Pidgin incorrectly handled large numbers ofsmileys. A remote attacker could send a specially crafted message and causePidgin to become unresponsive, leading to a denial of service.(CVE-2010-0423)





More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question