DescriptionHuzaifa S. Sidhpurwala
2014-01-24 08:46:54 UTC
A Heap-based buffer overflow was found in the way pidgin processed chunked HTTP responses. A malicious server or man-in-the-middle could send a large value for Content-Length and cause an integer overflow which could lead to a buffer overflow. This could cause pidgin to crash or possibly execute arbitary code with the permissions of the user running pidgin.
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Matt Jones of Volvent as the original reporter of this issue.
Comment 1Huzaifa S. Sidhpurwala
2014-01-27 06:17:18 UTC