Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu: 2100-1 Critical Pidgin Denial of Service Threats

ubuntu
Calendar Grey February 6, 2014
Scroller Ubuntu
Several significant security flaws in Pidgin, such as potential denial of service vulnerabilities, have been resolved in the latest Ubuntu updates.
Several security issues were fixed in Pidgin.

Summary

Several security issues were fixed in Pidgin.

Software Description:

- pidgin: graphical multi-protocol instant messaging client for X

Details:

Thijs Alkemade and Robert Vehse discovered that Pidgin incorrectly handled

the Yahoo! protocol. A remote attacker could use this issue to cause

Pidgin to crash, resulting in a denial of service. (CVE-2012-6152)

Jaime Breva Ribes discovered that Pidgin incorrectly handled the XMPP

protocol. A remote attacker could use this issue to cause Pidgin to crash,

resulting in a denial of service. (CVE-2013-6477)

It was discovered that Pidgin incorrecly handled long URLs. A remote

attacker could use this issue to cause Pidgin to crash, resulting in a

denial of service. (CVE-2013-6478)

Jacob Appelbaum discovered that Pidgin incorrectly handled certain HTTP

responses. A malicious remote server or a man in the middle could use this

issue to cause Pidgin to crash, resulting in a denial of service.

(CVE-2013-6479)

Daniel Atal...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libpurple0                      1:2.10.7-0ubuntu4.1.13.10.1
  pidgin                          1:2.10.7-0ubuntu4.1.13.10.1

Ubuntu 12.10:
  libpurple0                      1:2.10.6-0ubuntu2.3
  pidgin                          1:2.10.6-0ubuntu2.3

Ubuntu 12.04 LTS:
  libpurple0                      1:2.10.3-0ubuntu1.4
  pidgin                          1:2.10.3-0ubuntu1.4

After a standard system update you need to restart Pidgin to make all the
necessary changes.

References

https://ubuntu.com/security/notices/USN-2100-1

CVE-2012-6152, CVE-2013-6477, CVE-2013-6478, CVE-2013-6479,

CVE-2013-6481, CVE-2013-6482, CVE-2013-6483, CVE-2013-6484,

CVE-2013-6485, CVE-2013-6487, CVE-2013-6489, CVE-2013-6490,

CVE-2014-0020

Severity
critical
Lowest
Low
Medium
High
Critical

February 06, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.