Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 281958 - <=net-im/pidgin-2.5.8 - Overflow in msn prpl
Summary: <=net-im/pidgin-2.5.8 - Overflow in msn prpl
Status: RESOLVED DUPLICATE of bug 281545
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Security
URL: http://pidgin.im/news/security/?id=34
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-08-18 19:40 UTC by Mr. B
Modified: 2009-08-18 21:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mr. B 2009-08-18 19:40:14 UTC
There exists a buffer overflow in the 2.5.8 (and below) prpl. 2.5.9 and 2.6.0

Reproducible: Always

Steps to Reproduce:
1. Send specially crafted SLP messages consecutively
2. Cause buffer overflow
3. Take control of system or cause crash




Pidgin should be bumped to 2.5.9 and 2.6.0.
Comment 1 Mr. B 2009-08-18 19:42:24 UTC
Top line of the description was meant to say "2.5.9 and 2.6.0 are immune". Apologies.
Comment 2 7v5w7go9ub0o 2009-08-18 19:55:04 UTC
I'm about to d/l 2.6.0; how's it working for you?

(given it's a zero-day, I'm always leery about "surprises" that might have gotten into the code :-) )


Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2009-08-18 20:16:40 UTC

*** This bug has been marked as a duplicate of bug 281545 ***
Comment 4 Mr. B 2009-08-18 20:43:15 UTC
(In reply to comment #2)
> I'm about to d/l 2.6.0; how's it working for you?
> 
> (given it's a zero-day, I'm always leery about "surprises" that might have
> gotten into the code :-) )
> 
Very well, pity that MSN audio/video isn't working (though voice clips thereon are).
Just need to add:

farsight to USE

        farsight? (
                        media-plugins/gst-plugins-farsight
                        >=net-libs/farsight2-0.0.9 )

                $(use_enable farsight vv) \

...and of course: :P
#       strip-flags
#       replace-flags -O? -O2
Comment 5 7v5w7go9ub0o 2009-08-18 21:44:16 UTC
(In reply to comment #4)

> ...and of course: :P
> #       strip-flags
> #       replace-flags -O? -O2
> 

er... I don't understand this ?



Otherwise, are voice and/or video working on other protocols?

TIA
Comment 6 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-08-18 21:46:32 UTC
Can you please discuss this via email, IRC or somehow else? We don't really need the bugmail. Thanks.