Input validation error in Pidgin - CVE-2013-0273
Published: February 16, 2013 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
sametime.c in the Sametime protocol plugin in libpurple in Pidgin before 2.10.7 does not properly terminate long user IDs, which allows remote servers to cause a denial of service (application crash) via a crafted packet.
Affected software
Gentoo Linux
Slackware Linux
pidgin (Alpine package)
How to mitigate CVE-2013-0273
pidgin (Alpine package) - update to 2.10.7-r0
External References
- http://hg.pidgin.im/pidgin/main/rev/c31cf8de31cd
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.html
- http://www.pidgin.im/news/security/?id=67
- http://www.ubuntu.com/usn/USN-1746-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18340