Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2010-2528

Published: 30 July 2010

The clientautoresp function in family_icbm.c in the oscar protocol plugin in libpurple in Pidgin before 2.7.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via an X-Status message that lacks the expected end tag for a (1) desc or (2) title element.

Notes

AuthorNote
mdeslaur
2.7.x only, code isn't present in earlier versions

Priority

Low

Status

Package Release Status
pidgin
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Not vulnerable
(1:2.4.1-1ubuntu2.9)
jaunty Ignored
(end of life)
karmic Not vulnerable
(1:2.6.2-1ubuntu7.2)
lucid Not vulnerable
(1:2.6.6-1ubuntu4)
maverick Not vulnerable

upstream
Released (2.7.2)
Patches:
upstream: http://developer.pidgin.im/viewmtn/revision/info/8e8ff246492e45af8f8d0808296d6f2906794dc0