CVE-2013-6479

Published: 05 February 2014

util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.

Priority

Medium

Status

Package Release Status
pidgin
Launchpad, Ubuntu, Debian
Upstream
Released (2.10.8)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1:2.10.9-0ubuntu1)
Patches:
Upstream: http://hg.pidgin.im/pidgin/main/rev/cd529e1158d3