PT-2009-1053 · Pidgin+1 · Libpurple+4

Josh Bressers

·

Publicado

2009-05-22

·

Atualizado

2017-09-29

·

CVE-2009-1374

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pidgin versions prior to 2.5.6 libpurple-tcl versions prior to 2.5.6 libpurple-devel versions prior to 2.5.6 libpurple versions prior to 2.5.6
Description The issue is related to a buffer overflow in the decrypt out function, which allows remote attackers to cause a denial of service, resulting in an application crash. Multiple vulnerabilities in the libpurple package may lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Pidgin versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple-tcl versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple-devel versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple versions prior to 2.5.6, update to version 2.5.6 or later.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06319
BDU:2015-06321
BDU:2015-06323
CVE-2009-1374
RHSA-2009:1060
RHSA-2009_1060

Produtos afetados

Pidgin
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl