CVE Vulnerabilities

CVE-2011-1091

Published: Mar 14, 2011 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Affected Software

Name Vendor Start Version End Version
Pidgin Pidgin 2.6.0 (including) 2.6.0 (including)
Pidgin Pidgin 2.6.1 (including) 2.6.1 (including)
Pidgin Pidgin 2.6.2 (including) 2.6.2 (including)
Pidgin Pidgin 2.6.4 (including) 2.6.4 (including)
Pidgin Pidgin 2.6.5 (including) 2.6.5 (including)
Pidgin Pidgin 2.6.6 (including) 2.6.6 (including)
Pidgin Pidgin 2.7.0 (including) 2.7.0 (including)
Pidgin Pidgin 2.7.1 (including) 2.7.1 (including)
Pidgin Pidgin 2.7.2 (including) 2.7.2 (including)
Pidgin Pidgin 2.7.3 (including) 2.7.3 (including)
Pidgin Pidgin 2.7.4 (including) 2.7.4 (including)
Pidgin Pidgin 2.7.5 (including) 2.7.5 (including)
Pidgin Pidgin 2.7.6 (including) 2.7.6 (including)
Pidgin Pidgin 2.7.7 (including) 2.7.7 (including)
Pidgin Pidgin 2.7.8 (including) 2.7.8 (including)
Pidgin Pidgin 2.7.9 (including) 2.7.9 (including)
Pidgin Pidgin 2.7.10 (including) 2.7.10 (including)
Red Hat Enterprise Linux 4 RedHat pidgin-0:2.6.6-7.el4 *
Red Hat Enterprise Linux 5 RedHat pidgin-0:2.6.6-5.el5_7.1 *
Red Hat Enterprise Linux 6 RedHat pidgin-0:2.7.9-3.el6 *
Pidgin Ubuntu devel *
Pidgin Ubuntu hardy *
Pidgin Ubuntu karmic *
Pidgin Ubuntu lucid *
Pidgin Ubuntu maverick *
Pidgin Ubuntu natty *
Pidgin Ubuntu oneiric *
Pidgin Ubuntu upstream *

References