oss-sec mailing list archives
CVE Request -- Pidgin v2.7.6 <= x <= v2.7.8 -- MSN DirectConnect DoS (crash due NULL ptr dereference) after receiving a short P2P message
From: Jan Lieskovsky <jlieskov () redhat com>
Date: Mon, 27 Dec 2010 14:39:43 +0100
Hello Josh, Steve, vendors, Pidgin upstream has released the latest v2.7.9 version: [1] http://pidgin.im/pipermail/support/2010-December/009251.html addressing one security flaw in the MSN protocol: [2] http://pidgin.im/news/security/?id=49 Upstream changeset: [3] http://developer.pidgin.im/viewmtn/revision/info/aaa07bde3c51d3684391ae6ed86b6dbaeab5d031 References: [4] https://bugzilla.redhat.com/show_bug.cgi?id=665421 Further issue details from Stu Tomlinson (issue discoverer): <begin quote> I should clarify that because this is in the direct connection code it is not dependent on what the servers send us but rather what other clients send, so is susceptible to attack by malicious clients. I think only libpurple 2.7.6-2.7.8 are vulnerable because it was introduced by the MSN code remodelling that was merged in 2.7.6, not due to what the servers send. Regards, Stu. </end quote> Could you allocate a CVE id for this issue? Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
Current thread:
- CVE Request -- Pidgin v2.7.6 <= x <= v2.7.8 -- MSN DirectConnect DoS (crash due NULL ptr dereference) after receiving a short P2P message Jan Lieskovsky (Dec 27)