MEDIUM
(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
Published Oct 27, 2010
4.0
MEDIUMCVSS 2.0
EPSS 3.27%
Description
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
Affected products
No data.
OR
- ≤ 2.7.3
- 2.0.0
- 2.0.1
- 2.0.2
- 2.1.0
- 2.1.1
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.3.1
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.5.0
- 2.5.1
- 2.5.2
- 2.5.3
- 2.5.4
- 2.5.5
- 2.5.6
- 2.5.7
- 2.5.8
- 2.5.9
- 2.6.0
- 2.6.1
- 2.6.2
- 2.6.4
- 2.6.5
- 2.6.6
- 2.7.0
- 2.7.1
- 2.7.2
No data.
Red Hat Enterprise Linux 4
pidgin-0:2.6.6-5.el4_8
Fixed · RHSA-2010:0788
Red Hat Enterprise Linux 5
pidgin-0:2.6.6-5.el5_5
Fixed · RHSA-2010:0788
Red Hat Enterprise Linux 6
pidgin-0:2.6.6-6.el6_0
Fixed · RHSA-2010:0890
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | pidgin-0:2.6.6-5.el4_8 | Fixed | RHSA-2010:0788 |
| Red Hat Enterprise Linux 5 | pidgin-0:2.6.6-5.el5_5 | Fixed | RHSA-2010:0788 |
| Red Hat Enterprise Linux 6 | pidgin-0:2.6.6-6.el6_0 | Fixed | RHSA-2010:0890 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (29)
- http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcc x_refsource_CONFIRMPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050227.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050695.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050133.html vendor-advisoryx_refsource_FEDORA
- http://pidgin.im/news/security/?id=48 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/41893 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41899 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42075 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42294 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1024623 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462352 vendor-advisoryx_refsource_SLACKWARE
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:208 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/68773 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2010-0788.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2010-0890.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/44283 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1014-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/2753 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/2754 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2755 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2847 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/2851 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/2870 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-3711 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=641921 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62708 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-3711
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18506 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-3711
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 27, 2010
Updated Aug 7, 2024
Reserved Oct 1, 2010
Link CVE-2010-3711
CISA Vulnrichment
Updated n/a