exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 36384

Secunia Security Advisory 36384
Posted Sep 1, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability, a security issue, and a weakness have been reported in Pidgin, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or potentially compromise a user's system.

tags | advisory, denial of service
SHA-256 | a7038fab2631089816f2bffe8eb2a7593a0515b3e18ddedaeb74a4152c16f6d0

Secunia Security Advisory 36384

Change Mirror Download
----------------------------------------------------------------------

Do you have VARM strategy implemented?

(Vulnerability Assessment Remediation Management)

If not, then implement it through the most reliable vulnerability
intelligence source on the market.

Implement it through Secunia.

For more information visit:
http://secunia.com/advisories/business_solutions/

Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com

----------------------------------------------------------------------

TITLE:
Pidgin Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA36384

VERIFY ADVISORY:
http://secunia.com/advisories/36384/

DESCRIPTION:
A vulnerability, a security issue, and a weakness have been reported
in Pidgin, which can be exploited by malicious people to disclose
sensitive information, cause a DoS (Denial of Service), or
potentially compromise a user's system.

1) An error in the "msn_slplink_process_msg()" function when
processing MSN SLP messages can be exploited to corrupt memory.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in versions 2.5.8 and prior. Other
versions may also be affected.

2) The application connects to Jabberd servers that are not fully
compliant with the XMPP specifications without encryption, even if
the "Require SSL/TLS" setting is configured. This can be exploited to
potentially disclose sensitive information transmitted during an XMPP
session.

The security issue is reported in versions prior to 2.6.0.

3) An error when processing links received via the Yahoo Messenger
protocol can be exploited to crash the application.

The weakness is reported in version 2.6.0.

SOLUTION:
Update to version 2.6.1.

PROVIDED AND/OR DISCOVERED BY:
1) Federico Muttis, Core Security Technologies
2) Reported by bugdave in a Pidgin bug report.
3) Reported by adk in a Pidgin bug report.

CHANGELOG:
2009-08-24: Updated "Solution" section. Added vulnerabilities #2 and
#3 to the advisory. Updated credits and the "Original Advisory"
section.

ORIGINAL ADVISORY:
Pidgin:
http://www.pidgin.im/news/security/?id=32
http://www.pidgin.im/news/security/?id=35

Core Security Technologies:
http://www.coresecurity.com/content/libpurple-arbitrary-write

Pidgin Trac:
http://developer.pidgin.im/ticket/8131
http://developer.pidgin.im/ticket/9946

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    113 Files
  • 2
    Sep 2nd
    0 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    0 Files
  • 5
    Sep 5th
    0 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close