Информационная безопасность
[RU] switch to English


Повреждение памяти в Pidgin
дополнено с 26 июня 2008 г.
Опубликовано:26 мая 2009 г.
Источник:
SecurityVulns ID:9114
Тип:удаленная
Уровень опасности:
6/10
Описание:Повреждение памяти на получении файла по протоколу MSN, переполнение буфера при передаче файла через Jabber. Переполнение буфера в протоколе QQ.
Затронутые продукты:PIDGIN : Pidgin 2.4
CVE:CVE-2009-1376 (Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.)
 CVE-2009-1375 (The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol.)
 CVE-2009-1374 (Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.)
 CVE-2009-1373 (Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.)
Оригинальный текстdocumentGENTOO, [ GLSA 200905-07 ] Pidgin: Multiple vulnerabilities (26.05.2009)
 documentDEBIAN, [SECURITY] [DSA 1805-1] New pidgin packages fix several vulnerabilities (25.05.2009)
 documentjplopezy_(at)_gmail.com, Pidgin 2.4.1 Vulnerability (26.06.2008)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород