SB2011121701 - Multiple vulnerabilities in pidgin.im Pidgin



SB2011121701 - Multiple vulnerabilities in pidgin.im Pidgin

Published: December 17, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011121701
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2011-4601)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.


2) Input validation error (CVE-ID: CVE-2011-4603)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.


3) Input validation error (CVE-ID: CVE-2011-4602)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.


Remediation

Install update from vendor's website.

References