Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 305715 - <net-im/pidgin-2.6.6 multiple vulnerabilities (CVE-2010-{0277,0420,0423})
Summary: <net-im/pidgin-2.6.6 multiple vulnerabilities (CVE-2010-{0277,0420,0423})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-02-18 10:20 UTC by Dani Soufi
Modified: 2010-08-14 14:42 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dani Soufi 2010-02-18 10:20:14 UTC
Pidgin 2.6.6 was released earlier today fixing 3 security bugs: CVE-2010-0423 | CVE-2010-0420 | CVE-2010-0277 and many other fixes and changes according to this log http://developer.pidgin.im/wiki/ChangeLog

Reproducible: Always
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2010-02-18 20:33:51 UTC
New version is in the tree.
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-18 21:48:16 UTC
Thanks Dani and Peter.

Arches, please test and mark stable:
=net-im/pidgin-2.6.6
Target keywords : "alpha amd64 hppa ppc ppc64 x86"
Comment 3 Jeroen Roovers (RETIRED) gentoo-dev 2010-02-20 16:47:11 UTC
Stable for HPPA.
Comment 4 Thomas Kahle (RETIRED) gentoo-dev 2010-02-20 17:03:10 UTC
Tested on x86: Looks good.
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2010-02-21 22:41:17 UTC
x86 stable, thanks Thomas
Comment 6 Brent Baude (RETIRED) gentoo-dev 2010-02-23 15:31:44 UTC
ppc64 done
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2010-02-27 12:05:20 UTC
alpha/ia64/sparc stable
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-28 21:58:26 UTC
amd64 stable.
Comment 9 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-28 22:09:14 UTC
CVE-2010-0420 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0420):
  libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user
  chat (MUC) room is used, does not properly parse nicknames containing
  <br> sequences, which allows remote attackers to cause a denial of
  service (application crash) via a crafted nickname.

CVE-2010-0423 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0423):
  gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a
  denial of service (CPU consumption and application hang) by sending
  many smileys in a (1) IM or (2) chat.

Comment 10 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-28 22:10:12 UTC
CVE-2010-0277 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0277):
  slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6,
  including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a
  denial of service (memory corruption and application crash) or
  possibly have unspecified other impact via a malformed MSNSLP INVITE
  request in an SLP message, a different issue than CVE-2010-0013.

Comment 11 Joe Jezak (RETIRED) gentoo-dev 2010-03-09 22:09:38 UTC
Marked ppc stable.
Comment 12 Matthias Geerdsen (RETIRED) gentoo-dev 2010-06-15 20:27:38 UTC
ready for GLSA vote

there is also bug 324023
Comment 13 Tobias Heinlein (RETIRED) gentoo-dev 2010-08-14 14:42:10 UTC
DoS in client application → noglsa.