Release date:
Updated on:
Affected Systems:
Pidgin 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54322
Cve id: CVE-2012-3374
Pidgin is a multi-in-One world mainstream instant messaging software integration tool.
Pidgin 2.10.5 when parsing an inbound message that contains an inline image, the "mxit_show_message ()" function (libpurple/protocols/mxit/markup. c) There is a boundary error. Through the specially crafted RX message, stack buffer overflow can be caused and arbitrary code can be executed remotely.
<* Source: Ulf H & #228; rnhammar
Link: http://secunia.com/advisories/49831/
Http://www.pidgin.im/news/security/index.php? Id = 64
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Pidgin
------
Pidgin has released a Security Bulletin (ded90000ef42) and corresponding patches for this purpose:
Ded90000ef42: MXit buffer overflow
Link: http://www.pidgin.im/news/security/index.php? Id = 64