Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Red Hat Enterprise Linux 3: RHSA-2009:1535-01 Moderate: Pidgin DoS

red hat
Calendar Grey October 29, 2009
Dist Redhat Esm H88
Debian issued a significant security notice for Thunderbird responding to multiple vulnerabilities. Updating is crucial for protection.
An updated pidgin package that fixes several security issues is now available for Red Hat Enterprise Linux 3. This update has been rated as having moderate security impact by the ...

Solution

Before applying this update, make sure that all previously-released errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at

Summary

Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously.
An invalid pointer dereference bug was found in the way the Pidgin OSCAR protocol implementation processed lists of contacts. A remote attacker could send a specially-crafted contact list to a user running Pidgin, causing Pidgin to crash. (CVE-2009-3615)
A NULL pointer dereference flaw was found in the way the Pidgin IRC protocol plug-in handles IRC topics. A malicious IRC server could send a specially-crafted IRC TOPIC message, which once received by Pidgin, would lead to a denial of service (Pidgin crash). (CVE-2009-2703)
A NULL pointer dereference flaw was found in the way the Pidgin MSN protocol plug-in handles improper MSNSLP invitations. A remote attacker could send a specially-crafted MSNSLP invitation request, which once accepted by a valid Pidgin user, would lead to a denial of service (Pidgin crash). (CVE-2009-3083)
All Pidgin users should upgrade to this updated package, which contains backported patches to resolve these issues. Pidgin must be restarted for this update to take effect.

References

https://www.cve.org/CVERecord?id=CVE-2009-2703 https://www.cve.org/CVERecord?id=CVE-2009-3083 https://www.cve.org/CVERecord?id=CVE-2009-3615 https://access.redhat.com/security/updates/classification#moderate

Package List

Red Hat Enterprise Linux AS version 3:
Source:
i386: pidgin-1.5.1-6.el3.i386.rpm pidgin-debuginfo-1.5.1-6.el3.i386.rpm
ia64: pidgin-1.5.1-6.el3.ia64.rpm pidgin-debuginfo-1.5.1-6.el3.ia64.rpm
ppc: pidgin-1.5.1-6.el3.ppc.rpm pidgin-debuginfo-1.5.1-6.el3.ppc.rpm
s390: pidgin-1.5.1-6.el3.s390.rpm pidgin-debuginfo-1.5.1-6.el3.s390.rpm
s390x: pidgin-1.5.1-6.el3.s390x.rpm pidgin-debuginfo-1.5.1-6.el3.s390x.rpm
x86_64: pidgin-1.5.1-6.el3.x86_64.rpm pidgin-debuginfo-1.5.1-6.el3.x86_64.rpm
Red Hat Desktop version 3:
Source:
i386: pidgin-1.5.1-6.el3.i386.rpm pidgin-debuginfo-1.5.1-6.el3.i386.rpm
x86_64: pidgin-1.5.1-6.el3.x86_64.rpm pidgin-debuginfo-1.5.1-6.el3.x86_64.rpm
Red Hat Enterprise Linux ES version 3:
Source:
i386: pidgin-1.5.1-6.el3.i386.rpm pidgin-debuginfo-1.5.1-6.el3.i386.rpm
ia64: pidgin-1.5.1-6.el3.ia64.rpm pidgin-debuginfo-1.5.1-6.el3.ia64.rpm
x86_64: pidgin-1.5.1-6.el3.x86_64.rpm pidgin-debuginfo-1.5.1-6.el3.x86_64.rpm
Red Hat Enterprise Linux WS version 3:
Source:
i386: pidgin-1.5.1-6.el3.i386.rpm pidgin-debuginfo-1.5.1-6.el3.i386.rpm
ia64: pidgin-1.5.1-6.el3.ia64.rpm pidgin-debuginfo-1.5.1-6.el3.ia64.rpm
x86_64: pidgin-1.5.1-6.el3.x86_64.rpm pidgin-debuginfo-1.5.1-6.el3.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and

Read the Full Advisory


Advisory ID: RHSA-2009:1535-01
Product: Red Hat Enterprise Linux
Issue date: 2009-10-29

Topic

An updated pidgin package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 3.This update has been rated as having moderate security impact by the RedHat Security Response Team.

Relevant Releases Architectures

Red Hat Desktop version 3 - i386, x86_64

Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64

Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64

Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

Bugs Fixed

521823 - CVE-2009-2703 Pidgin: NULL pointer dereference by handling IRC topic(s) (DoS)

521832 - CVE-2009-3083 Pidgin: NULL pointer dereference by processing incomplete MSN SLP invite (DoS)

529357 - CVE-2009-3615 Pidgin: Invalid pointer dereference (crash) after receiving contacts from SIM IM client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here