Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Ubuntu 11.04 USN-1273-1 Critical: Pidgin Denial Of Service

ubuntu
Calendar Grey November 21, 2011
Scroller Ubuntu
The latest Ubuntu Security Announcement USN-1273-1 discloses critical flaws in Pidgin, which could lead to application crashes when processing malformed data packets.
Pidgin could be made to crash if it received specially crafted network traffic.

Summary

Pidgin could be made to crash if it received specially crafted network

traffic.

Software Description:

- pidgin: multi-protocol instant messaging client

Details:

Marius Wachtler discovered that Pidgin incorrectly handled malformed YMSG

messages in the Yahoo! protocol handler. A remote attacker could send a

specially crafted message and cause Pidgin to crash, leading to a denial

of service. This issue only affected Ubuntu 10.04 LTS and 10.10.

(CVE-2011-1091)

Marius Wachtler discovered that Pidgin incorrectly handled HTTP 100

responses in the MSN protocol handler. A remote attacker could send a

specially crafted message and cause Pidgin to crash, leading to a denial

of service. (CVE-2011-3184)

Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8

sequences in the SILC protocol handler. A remote attacker could send a

specially crafted message and cause Pidgin to crash, leading to a denial

of service. (CVE-2011-3594)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  pidgin                          1:2.7.11-1ubuntu2.1

Ubuntu 10.10:
  pidgin                          1:2.7.3-1ubuntu3.3

Ubuntu 10.04 LTS:
  pidgin                          1:2.6.6-1ubuntu4.4

After a standard system update you need to restart Pidgin to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1273-1

CVE-2011-1091, CVE-2011-3184, CVE-2011-3594

Severity
critical
Lowest
Low
Medium
High
Critical

November 21, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.