Back

MEDIUM

Pidgin: Multiple NULL pointer dereference flaws in Yahoo protocol plug-in

Published Mar 14, 2011

Description

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Affected products

Remediation

Red Hat statement

This issue affects the versions of pidgin package as shipped with Red Hat Enterprise Linux 4, 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Metrics

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 14, 2011
Updated Aug 6, 2024
Reserved Feb 24, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Mar 10, 2011