PT-2008-1055 · Libpurple+2 · Libpurple+4

Juan Pablo Lopez Yacubian

·

Published

2008-07-01

·

Updated

2024-06-15

·

CVE-2008-2955

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pidgin version 2.4.1 libpurple-devel versions 2.5.2 and earlier libpurple-tcl versions 2.5.2 and earlier libpurple versions 2.5.2 and earlier
Description The issue allows remote attackers to cause a denial of service, potentially leading to a crash, by sending a message with a long filename containing certain characters. This can be triggered in the msn slplink process msg function. Multiple vulnerabilities in the libpurple package can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Pidgin version 2.4.1, consider updating to a newer version to mitigate the risk. For libpurple-devel versions 2.5.2 and earlier, restrict access to the msn slplink process msg function until a patch is available. For libpurple-tcl versions 2.5.2 and earlier, avoid using the vulnerable libpurple-tcl package until the issue is resolved. For libpurple versions 2.5.2 and earlier, disable the vulnerable functions temporarily to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06318
BDU:2015-06320
BDU:2015-06322
CVE-2008-2955
OPENSUSE-SU-2024:11172-1
RHSA-2008:1023
RHSA-2008_1023

Affected Products

Pidgin
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl