CVE-2012-2214
Publication date 3 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pidgin | 12.04 LTS precise |
Fixed 1:2.10.3-0ubuntu1.1
|
| 11.10 oneiric |
Fixed 1:2.10.0-0ubuntu2.1
|
|
| 11.04 natty |
Not affected
|
|
| 10.04 LTS lucid |
Not affected
|
|
| 8.04 LTS hardy | Ignored end of life |
Notes
Patch details
| Package | Patch details |
|---|---|
| pidgin |
References
Related Ubuntu Security Notices (USN)
- USN-1500-1
- Pidgin vulnerabilities
- 9 July 2012