Release date:
Updated on:
Affected Systems:
Pidgin 2.x
Unaffected system:
Pidgin 2.10.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53400
Pidgin is a multi-in-One world mainstream instant messaging software integration tool.
A security vulnerability exists in the implementation of Pidgin, which can be exploited by malicious users to cause DOS.
1) errors in the lis5 proxy processing code (libpurple/proxy. c) can be caused by a reference of invalid pointers or a crash by sending specially crafted file conversion requests;
2) when processing a message with certain characters or character encoding, the "msn_message_parse_payload ()" function libpurple/protocols/msn/msg. c)
Can be exploited to cause a crash.
<* Source: Fabian Yamaguchi
Link: http://secunia.com/advisories/49036/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Pidgin
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://pidgin.im/pidgin/home/