PT-2009-1053 · Pidgin+1 · Libpurple+4

Josh Bressers

·

Published

2009-05-22

·

Updated

2017-09-29

·

CVE-2009-1374

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Pidgin versions prior to 2.5.6 libpurple-tcl versions prior to 2.5.6 libpurple-devel versions prior to 2.5.6 libpurple versions prior to 2.5.6
Description The issue is related to a buffer overflow in the decrypt out function, which allows remote attackers to cause a denial of service, resulting in an application crash. Multiple vulnerabilities in the libpurple package may lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For Pidgin versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple-tcl versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple-devel versions prior to 2.5.6, update to version 2.5.6 or later. For libpurple versions prior to 2.5.6, update to version 2.5.6 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06319
BDU:2015-06321
BDU:2015-06323
CVE-2009-1374
RHSA-2009:1060
RHSA-2009_1060

Affected Products

Pidgin
Red Hat
Libpurple
Libpurple-Devel
Libpurple-Tcl