Back

MEDIUM

pidgin: Remote crash in MSN protocol plugin

Published Aug 29, 2011

Description

The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security flaw. As a malicious MSN server is needed, there are far worlse implications to a user connecting to an untrusted server than a DoS.

Metrics

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 29, 2011
Updated Aug 6, 2024
Reserved Aug 19, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Aug 20, 2011