Back

MEDIUM

Pidgin: MSN DirectConnect DoS (crash) after receiving a short P2P message

Published Jan 7, 2011

Description

directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnect (aka direct connection) session.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of pidgin package as shipped with Red Hat Enterprise Linux 4, 5, and 6 as this issue is specific to versions of libpurple from 2.7.6 up to 2.7.8.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 7, 2011
Updated Aug 7, 2024
Reserved Dec 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 26, 2010