Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3711

Опубликовано: 20 окт. 2010
Источник: redhat
CVSS2: 5

Описание

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3pidginAffected
Red Hat Enterprise Linux 4pidginFixedRHSA-2010:078821.10.2010
Red Hat Enterprise Linux 5pidginFixedRHSA-2010:078821.10.2010
Red Hat Enterprise Linux 6pidginFixedRHSA-2010:089016.11.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=641921(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

nvd
больше 14 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

debian
больше 14 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return ...

github
около 3 лет назад

libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

oracle-oval
больше 14 лет назад

ELSA-2010-0890: pidgin security update (MODERATE)

5 Medium

CVSS2