[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2011:183 -- Mandriva pidgin

ID: oval:org.secpod.oval:def:301118Date: (C)2012-01-07   (M)2023-07-28
Class: PATCHFamily: unix




Multiple vulnerabilities has been discovered and corrected in pidgin: When receiving various stanzas related to voice and video chat, the XMPP protocol plugin failed to ensure that the incoming message contained all required fields, and would crash if certain fields were missing. When receiving various messages related to requesting or receiving authorization for adding a buddy to a buddy list, the oscar protocol plugin failed to validate that a piece of text was UTF-8. In some cases invalid UTF-8 data would lead to a crash . When receiving various incoming messages, the SILC protocol plugin failed to validate that a piece of text was UTF-8. In some cases invalid UTF-8 data would lead to a crash . This update provides pidgin 2.10.1, which is not vulnerable to these issues.

Platform:
Mandriva Linux 2010.1
Product:
pidgin
Reference:
MDVSA-2011:183
CVE-2011-3594
CVE-2011-4601
CVE    2
CVE-2011-4601
CVE-2011-3594
CPE    1
cpe:/o:mandriva:linux:2010.1

© SecPod Technologies