Bug 742450 - pidgin: Heap-based buffer overflow by processing certain SILC private messages
Summary: pidgin: Heap-based buffer overflow by processing certain SILC private messages
Keywords:
Status: CLOSED DUPLICATE of bug 743481
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 742457
Blocks: 742574
TreeView+ depends on / blocked
 
Reported: 2011-09-30 07:57 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:47 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-10-05 05:08:34 UTC
Embargoed:


Attachments (Terms of Use)

Description Jan Lieskovsky 2011-09-30 07:57:53 UTC
Pidgin is a Gtk+ based multiprotocol instant messaging client. The SILC Purple plug-in allows Pidgin to use the Secure Internet Live Conferencing (SILC) protocol.

A heap-based buffer overflow flaw was found in the way the SILC Purple Pidgin protocol plug-in escaped certain UTF-8 private messages. If a Pidgin client received a specially-crafted SILC message, it could cause Pidgin to crash, or, potentially lead to arbitrary code execution with the privileges of the user running Pidgin.

References:
[1] http://developer.pidgin.im/ticket/14636

Comment 1 Jan Lieskovsky 2011-09-30 07:59:36 UTC
This issue affects the versions of the pidgin package, as shipped with Red Hat Enterprise Linux 4 and 5.

--

This issue did NOT affect the version of the pidgin package, as shipped with Red Hat Enterprise Linux 6 since the Pidgin SILC plug-in has been disabled there.

--

This issue affects the versions of the pidgin package, as shipped with Fedora release of 14 and 15.

Comment 4 Jan Lieskovsky 2011-09-30 08:17:00 UTC
Created pidgin tracking bugs for this issue

Affects: fedora-all [bug 742457]

Comment 8 Huzaifa S. Sidhpurwala 2011-10-05 05:08:34 UTC

*** This bug has been marked as a duplicate of bug 743481 ***

Comment 9 Fedora Update System 2012-01-05 20:55:07 UTC
pidgin-2.10.1-1.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2012-01-07 22:59:24 UTC
pidgin-2.10.1-1.fc15 has been pushed to the Fedora 15 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.