Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 197006 - net-im/pidgin <2.2.2 HTML Processing Denial of Service Vulnerability
Summary: net-im/pidgin <2.2.2 HTML Processing Denial of Service Vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Net-im project
URL: http://secunia.com/advisories/27372/
Whiteboard: B3 [ebuild]
Keywords:
: CVE-2007-4999 198746 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-10-25 08:36 UTC by Kalidarn
Modified: 2007-11-10 22:26 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kalidarn 2007-10-25 08:36:36 UTC
* General changes
o Various bug and memory leak fixes 

* Windows-specific changes
o Updated gtkspell to include a patch to share Aspell dictionaries among all the input fields to avoid excessive memory usage.
o Updated libxml2 to 2.6.30
o Bonjour protocol now appears even if Bonjour for Windows isn't present (displays message indicating Bonjour for Windows must be installed if you try to log in and it isn't installed).
o libpurple now looks for a default prefs.xml in the CSIDL_COMMON_APPDATA directory (e.g. \Documents and Settings\All Users\Application Data\purple\prefs.xml) similarly to how this is done on other platforms. 

Reproducible: Always
Comment 1 Tobias Heinlein (RETIRED) gentoo-dev 2007-10-25 22:19:10 UTC
As version 2.2.2 fixes a security issue, I'll transform this bug report into a security bug.


A weakness has been reported in Pidgin, which can be exploited by
malicious people to cause a DoS (Denial of Service).

The weakness is caused due to a NULL-pointer dereference error when
processing messages with invalid HTML code and can be exploited to
cause libpurple to crash.

Successful exploitation may require that HTML logging is used. (If this is not the default case, re-rate to C3.)
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2007-10-25 22:20:34 UTC
net-im, please advise and/or create an updated ebuild.
Comment 3 Olivier Crete (RETIRED) gentoo-dev 2007-10-26 01:28:25 UTC
Ok, new version is in the tree
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-10-26 07:27:14 UTC
Thx for the bug keytoaster but we usually don't handle simple crash bugs in client applications. So I'm reassigning this one back.
Comment 5 Olivier Crete (RETIRED) gentoo-dev 2007-10-27 18:25:10 UTC
Alright, then if its not security, we can wait one month to stable it.
Comment 6 Olivier Crete (RETIRED) gentoo-dev 2007-10-31 01:45:49 UTC
*** Bug 197580 has been marked as a duplicate of this bug. ***
Comment 7 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-11-10 22:26:20 UTC
*** Bug 198746 has been marked as a duplicate of this bug. ***