CVE Vulnerabilities

CVE-2011-1091

Published: Mar 14, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Affected Software

NameVendorStart VersionEnd Version
PidginPidgin2.6.0 (including)2.6.0 (including)
PidginPidgin2.6.1 (including)2.6.1 (including)
PidginPidgin2.6.2 (including)2.6.2 (including)
PidginPidgin2.6.4 (including)2.6.4 (including)
PidginPidgin2.6.5 (including)2.6.5 (including)
PidginPidgin2.6.6 (including)2.6.6 (including)
PidginPidgin2.7.0 (including)2.7.0 (including)
PidginPidgin2.7.1 (including)2.7.1 (including)
PidginPidgin2.7.2 (including)2.7.2 (including)
PidginPidgin2.7.3 (including)2.7.3 (including)
PidginPidgin2.7.4 (including)2.7.4 (including)
PidginPidgin2.7.5 (including)2.7.5 (including)
PidginPidgin2.7.6 (including)2.7.6 (including)
PidginPidgin2.7.7 (including)2.7.7 (including)
PidginPidgin2.7.8 (including)2.7.8 (including)
PidginPidgin2.7.9 (including)2.7.9 (including)
PidginPidgin2.7.10 (including)2.7.10 (including)
Red Hat Enterprise Linux 4RedHatpidgin-0:2.6.6-7.el4*
Red Hat Enterprise Linux 5RedHatpidgin-0:2.6.6-5.el5_7.1*
Red Hat Enterprise Linux 6RedHatpidgin-0:2.7.9-3.el6*
PidginUbuntudevel*
PidginUbuntuhardy*
PidginUbuntukarmic*
PidginUbuntulucid*
PidginUbuntumaverick*
PidginUbuntunatty*
PidginUbuntuoneiric*
PidginUbuntuupstream*

References