Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Ubuntu 15.10: USN-3031-1 Moderate: Pidgin DoS and Code Risk

ubuntu
Calendar Grey July 12, 2016
Scroller Ubuntu
Ubuntu's Pidgin faced security flaws which could lead to system crashes or remote exploitation, demanding immediate patches.
Pidgin could be made to crash or run programs if it received specially crafted network traffic.

Summary

Pidgin could be made to crash or run programs if it received

specially crafted network traffic.

Software Description:

- pidgin: graphical multi-protocol instant messaging client for X

Details:

Yves Younan discovered that Pidgin contained multiple issues in the MXit

protocol support. A remote attacker could use this issue to cause Pidgin to

crash, resulting in a denial of service, or possibly execute arbitrary

code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libpurple0                      1:2.10.11-0ubuntu4.2

Ubuntu 14.04 LTS:
  libpurple0                      1:2.10.9-0ubuntu3.3

Ubuntu 12.04 LTS:
  libpurple0                      1:2.10.3-0ubuntu1.7

After a standard system update you need to restart Pidgin to make all the
necessary changes.

References

https://ubuntu.com/security/notices/USN-3031-1

CVE-2016-2365, CVE-2016-2366, CVE-2016-2367, CVE-2016-2368,

CVE-2016-2369, CVE-2016-2370, CVE-2016-2371, CVE-2016-2372,

CVE-2016-2373, CVE-2016-2374, CVE-2016-2375, CVE-2016-2376,

CVE-2016-2377, CVE-2016-2378, CVE-2016-2380, CVE-2016-4323

Severity
important
Lowest
Low
Medium
High
Critical

July 12, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.