Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

SUSE Linux 11 SP2: 2013:0388-1 Important: Pidgin Remote Code Exec

suse
Calendar Grey March 4, 2013
Scroller Suse
Essential upgrade for pidgin resolves numerous vulnerabilities. Apply the fix without delay to protect against threats.
An update that fixes four vulnerabilities is now available

Summary

pidgin was updated to fix 4 security issues: * Fixed a crash when receiving UPnP responses with abnormally long values. (CVE-2013-0274, bnc#804742) * Fixed a crash in Sametime protocol when a malicious server sends us an abnormally long user ID. (CVE-2013-0273, bnc#804742) * Fixed a bug where the MXit server or a man-in-the-middle could potentially send specially crafted data that could overflow a buffer and lead to a crash or remote code execution.(CVE-2013-0272, bnc#804742) * Fixed a bug where a remote MXit user could possibly specify a local file path to be written to. (CVE-2013-0271, bnc#804742) Security Issue references: * CVE-2013-0271 * CVE-2013-0272

References

#804742

Cross- CVE-2013-0271 CVE-2013-0272 CVE-2013-0273

CVE-2013-0274

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2013-0271.html

https://www.suse.com/security/cve/CVE-2013-0272.html

https://www.suse.com/security/cve/CVE-2013-0273.html

https://www.suse.com/security/cve/CVE-2013-0274.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0388-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.