pidgin: insufficient input validation in msn_slplink_process_msg()
Published Aug 20, 2009
10.0
HIGHCVSS 2.0
EPSS 20.29%
Description
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.
Affected products
No data.
- ≤ 1.3.5
- 1.2.7
- 1.3
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- ≤ 2.5.8
- 2.0.0
- 2.0.1
- 2.0.2
- 2.1.0
- 2.1.1
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.3.1
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.5.0
- 2.5.1
- 2.5.2
- 2.5.3
- 2.5.4
- 2.5.6
- 2.5.7
No data.
Red Hat Enterprise Linux 3
pidgin-0:1.5.1-4.el3
Fixed · RHSA-2009:1218
Red Hat Enterprise Linux 4
pidgin-0:2.5.9-1.el4
Fixed · RHSA-2009:1218
Red Hat Enterprise Linux 5
pidgin-0:2.5.9-1.el5
Fixed · RHSA-2009:1218
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | pidgin-0:1.5.1-4.el3 | Fixed | RHSA-2009:1218 |
| Red Hat Enterprise Linux 4 | pidgin-0:2.5.9-1.el4 | Fixed | RHSA-2009:1218 |
| Red Hat Enterprise Linux 5 | pidgin-0:2.5.9-1.el5 | Fixed | RHSA-2009:1218 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Users can lower the impact of this flaw by making sure their privacy settings only allow Pidgin to accept messages from the users on their buddy list. This will prevent exploitation of this flaw by other random MSN users.
References (23)
- http://developer.pidgin.im/viewmtn/revision/info/6f7343166c673bf0496ecb1afec9b633c1d54a0e x_refsource_CONFIRMPatch
- http://developer.pidgin.im/wiki/ChangeLog x_refsource_CONFIRM
- http://secunia.com/advisories/36384 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36392 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36401 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/36402 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36708 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37071 third-party-advisoryx_refsource_SECUNIA
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-266908-1 vendor-advisoryx_refsource_SUNALERT
- http://www.coresecurity.com/content/libpurple-arbitrary-write x_refsource_MISCExploit
- http://www.debian.org/security/2009/dsa-1870 vendor-advisoryx_refsource_DEBIANPatch
- http://www.exploit-db.com/exploits/9615 exploitx_refsource_EXPLOIT-DB
- http://www.pidgin.im/news/security/?id=34 x_refsource_CONFIRMVendor Advisory
- http://www.vupen.com/english/advisories/2009/2303 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/2663 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-2694 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=514957 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2686 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2694
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10319 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6320 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2009-1218.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2009-2694
Change history (0)
No recorded changes yet.