Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 684685 - (CVE-2011-4922) CVE-2011-4922 Cipher API information disclosure in pidgin
CVE-2011-4922 Cipher API information disclosure in pidgin
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20110210,reported=2...
: Reopened, Security
Depends On: 684119 684120
Blocks:
  Show dependency treegraph
 
Reported: 2011-03-14 04:42 EDT by Huzaifa S. Sidhpurwala
Modified: 2015-07-30 09:07 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-30 09:07:43 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0616 normal SHIPPED_LIVE Low: pidgin security and bug fix update 2011-05-19 07:09:02 EDT

  None (edit)
Description Huzaifa S. Sidhpurwala 2011-03-14 04:42:15 EDT
It was discovered that libpurple versions prior to 2.7.10 
do not properly clear certain data structures used in libpurple/cipher.c 
prior to freeing. 
An attacker could potentially extract partial information from memory 
regions freed by libpurple.

References:
http://pidgin.im/news/security/?id=50

This is fixed in pidgin version 2.7.10
Comment 3 Huzaifa S. Sidhpurwala 2011-03-14 04:45:55 EDT
Created pidgin tracking bugs for this issue

Affects: fedora-all [bug 684120]
Comment 6 Jan Lieskovsky 2011-03-21 10:23:53 EDT
CVE Request:
[2] http://www.openwall.com/lists/oss-security/2011/03/21/6
Comment 7 errata-xmlrpc 2011-05-19 07:09:11 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0616 https://rhn.redhat.com/errata/RHSA-2011-0616.html
Comment 8 errata-xmlrpc 2011-05-19 09:41:14 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0616 https://rhn.redhat.com/errata/RHSA-2011-0616.html
Comment 9 Vincent Danen 2012-01-09 17:25:04 EST
A CVE was finally issued (CVE-2011-4922):

http://www.openwall.com/lists/oss-security/2012/01/04/13
Comment 10 Vincent Danen 2012-01-09 17:28:32 EST
Statement:

The Red Hat Security Response Team has rated this issue as having low security impact. A future update may address this issue in Red Hat Enterprise Linux 4 or 5 (it has been addressed in Red Hat Enterprise Linux 6). For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Comment 11 Vincent Danen 2012-01-09 17:29:01 EST
Pidgin 2.6.6 (shipped with Red Hat Enterprise Linux 4 and 5) is affected by this.

Note You need to log in before you can comment on or make changes to this bug.