MEDIUM
The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name
Published Sep 8, 2009
5.0
MEDIUMCVSS 2.0
EPSS 2.52%
Description
The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name.
Affected products
No data.
AND
OR
- ≤ 2.6.1
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.2
- 2.1.0
- 2.1.1
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.3.1
- 2.4.0
- 2.4.0
- 2.4.1
- 2.4.1
- 2.4.2
- 2.4.2
- 2.4.3
- 2.4.3
- 2.5.0
- 2.5.0
- 2.5.1
- 2.5.2
- 2.5.2
- 2.5.3
- 2.5.3
- 2.5.4
- 2.5.4
- 2.5.5
- 2.5.5
- 2.5.6
- 2.5.7
- 2.5.8
- 2.5.9
- 2.6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of Pidgin packages, as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Weaknesses (1)
References (9)
- http://developer.pidgin.im/viewmtn/revision/diff/92ce3e48744b40fb0fea89e3de5e44bedb100c07/with/567e16cbc46168f52482e5ec27626c48e7a5ba95/libpurple/protocols/msn/slpcall.c x_refsource_CONFIRMPatchVendor Advisory
- http://developer.pidgin.im/viewmtn/revision/info/567e16cbc46168f52482e5ec27626c48e7a5ba95 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/36601 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.pidgin.im/news/security/index.php?id=38 x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/36277 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-3084 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3084
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6338 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3084
| Link | Providers | Tags |
|---|---|---|
| http://developer.pidgin.im/viewmtn/revision/diff/92ce3e48744b40fb0fea89e3de5e44bedb100c07/with/567e16cbc46168f52482e5ec27626c48e7a5ba95/libpurple/protocols/msn/slpcall.c | x_refsource_CONFIRMPatchVendor Advisory | |
| http://developer.pidgin.im/viewmtn/revision/info/567e16cbc46168f52482e5ec27626c48e7a5ba95 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://secunia.com/advisories/36601 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.pidgin.im/news/security/index.php?id=38 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.securityfocus.com/bid/36277 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-3084 | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3084 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6338 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2009-3084 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 8, 2009
Updated Aug 7, 2024
Reserved Sep 8, 2009
Link CVE-2009-3084
CISA Vulnrichment
Updated n/a