CVE-2008-2927
published 2008-07-07CVE-2008-2927: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2)…
PriorityP333medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.33%
90.1th percentile
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adium | adium | <= 1.2.7 | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| adium | adium | — | — |
| debian | pidgin | < pidgin 2.4.3-1 (bookworm) | pidgin 2.4.3-1 (bookworm) |
| debian | pidgin | < pidgin 2.5.6-1 (bookworm) | pidgin 2.5.6-1 (bookworm) |
| pidgin | pidgin | <= 2.5.5 | — |
| pidgin | pidgin | <= 2.4.2 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pidgin incomplete fix for CVE-2008-2927
vendor_redhat·2009-05-02·CVSS 6.8
CVE-2009-1376 [MEDIUM] pidgin incomplete fix for CVE-2008-2927
pidgin incomplete fix for CVE-2008-2927
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
Debian
CVE-2009-1376: pidgin - Multiple integer overflows in the msn_slplink_process_msg functions in the MSN p...
vendor_debian·2009·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376: pidgin - Multiple integer overflows in the msn_slplink_process_msg functions in the MSN p...
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
Scope: local
bookworm: resolved (fixed in 2.5.6-1)
bullseye: resolved (fixed in 2.5.6-1)
forky: resolved (fixed in 2.5.6-1)
sid: resolved (fixed in 2.5.6-1)
trixie: resolved (fixed in 2.5.6-1)
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2008-11-24·CVSS 6.8
CVE-2008-2927 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
It was discovered that Pidgin did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a specially
crafted message and possibly execute arbitrary code with user privileges.
(CVE-2008-2927)
It was discovered that Pidgin did not properly handle file transfers containing
a long filename and special characters in the MSN protocol handler. A remote
attacker could send a specially crafted filename in a file transfer request
and cause Pidgin to crash, leading to a denial of service. (CVE-2008-2955)
It was discovered that Pidgin did not impose resource limitations in the UPnP
service. A remote attacker could cause Pidgin to download arbitrary files
and cause a denial of service fro
Ubuntu
Gaim vulnerability
vendor_ubuntu·2008-11-24·CVSS 6.8
CVE-2008-2927 [MEDIUM] Gaim vulnerability
Title: Gaim vulnerability
Summary: Gaim vulnerability
It was discovered that Gaim did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a specially
crafted message and possibly execute arbitrary code with user privileges.
(CVE-2008-2927)
Instructions: After a standard system upgrade you need to restart Gaim to effect
the necessary changes.
Red Hat
pidgin MSN integer overflow
vendor_redhat·2008-07-04·CVSS 6.8
CVE-2008-2927 [MEDIUM] CWE-190 pidgin MSN integer overflow
pidgin MSN integer overflow
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
Debian
CVE-2008-2927: pidgin - Multiple integer overflows in the msn_slplink_process_msg functions in the MSN p...
vendor_debian·2008·CVSS 6.8
CVE-2008-2927 [MEDIUM] CVE-2008-2927: pidgin - Multiple integer overflows in the msn_slplink_process_msg functions in the MSN p...
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
Scope: local
bookworm: resolved (fixed in 2.4.3-1)
bullseye: resolved (fixed in 2.4.3-1)
forky: resolved (fixed in 2.4.3-1)
sid: resolved (fixed in 2.4.3-1)
trixie: resolved (fixed in 2.4.3-1)
GHSA
GHSA-p33h-j5pj-5f6r: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-1376 [MEDIUM] GHSA-p33h-j5pj-5f6r: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
GHSA
GHSA-xgwj-qm2p-hcpc: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2008-2927 [MEDIUM] GHSA-xgwj-qm2p-hcpc: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
OSV
CVE-2009-1376: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
osv·2009-05-26·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.
OSV
CVE-2008-2927: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
osv·2008-07-07·CVSS 6.8
CVE-2008-2927 [MEDIUM] CVE-2008-2927: Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2694 pidgin: insufficient input validation in msn_slplink_process_msg()
bugzilla·2009-07-31·CVSS 6.8
CVE-2009-2694 [MEDIUM] CVE-2009-2694 pidgin: insufficient input validation in msn_slplink_process_msg()
CVE-2009-2694 pidgin: insufficient input validation in msn_slplink_process_msg()
Core Security Technologies reported that previous upstream fixes addressing insufficient input validation flaw in pidgin / libpurple in function msn_slplink_process_msg() are inefficient and can be bypassed. This flaw allows an attacker to overwrite pidgin's memory and possibly execute arbitrary code with the privileges of the user running application using libpurple.
This issue was previously tracked as CVE-2008-2927 (bug #453764) and CVE-2009-1376 (bug #500493, incomplete fix).
Discussion:
Mitigation:
Users can lower the impact of this flaw by making sure their privacy settings only allow Pidgin to accept messages from the users on their buddy list. This will prevent exploitation of this flaw by other r
Bugzilla
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
bugzilla·2009-05-26·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #500493: CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
bug #500488: CVE-2009-1373 pidgin file transfer buffer overflow
bug #500490: CVE-2009-1374 pidgin DoS when decrypting qq packets
bug #500491: CVE-2009-1375 pidgin PurpleCircBuffer corruption
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE
Bugzilla
CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
bugzilla·2009-05-12·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
The integer overflow fix for CVE-2008-2927 was incomplete on 32 bit
platforms. If a Pidgin user can receive a specially crafted MSN message,
it may be possible to execute arbitrary code with the permissions of the
user running Pidgin.
This flaw is only exploitable by individuals who can message a user, which
is controlled by the Pidgin privacy setting. The default setting is to
only allow messages from users in the buddy list.
Discussion:
Link to upstream advisory:
http://www.pidgin.im/news/security//?id=32
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Via RHSA-2009:1059 https://rhn.redhat.com/errata/RHSA-2009-1059.html
---
This issue has been addressed in following products:
Red Hat Ent
Bugzilla
CVE-2008-2927 pidgin MSN integer overflow
bugzilla·2008-07-02·CVSS 6.8
CVE-2008-2927 [MEDIUM] CVE-2008-2927 pidgin MSN integer overflow
CVE-2008-2927 pidgin MSN integer overflow
An integer overflow in Pidgin's MSN protocol handler could allow malformed SLP
message to cause an integer overflow, which could result in arbitrary code
execution.
This flaw is only exploitable by individuals who can message a user, which is
controlled by the Pidgin privacy setting. The default setting is to only allow
messages from users in the buddy list.
Discussion:
Created attachment 310788
Proposed upstream patch
---
#
#
# patch "libpurple/protocols/msnp9/slplink.c"
# from [0148f31961bbe4a9a992377e70db082952505db4]
# to [f65596ea173bf7c9c1114edd7599140f470e7788]
#
--- libpurple/protocols/msnp9/slplink.c 0148f31961bbe4a9a992377e70db082952505db4
+++ libpurple/protocols/msnp9/slplink.c f65596ea173bf7c9c1114edd7599140f470e7788
@@ -597,7 +59
http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msn/slplink.chttp://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msnp9/slplink.chttp://secunia.com/advisories/30971http://secunia.com/advisories/31016http://secunia.com/advisories/31105http://secunia.com/advisories/31387http://secunia.com/advisories/31642http://secunia.com/advisories/32859http://secunia.com/advisories/32861http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0246http://www.debian.org/security/2008/dsa-1610http://www.mandriva.com/security/advisories?name=MDVSA-2008:143http://www.mandriva.com/security/advisories?name=MDVSA-2009:127http://www.openwall.com/lists/oss-security/2008/07/03/6http://www.openwall.com/lists/oss-security/2008/07/04/1http://www.pidgin.im/news/security/?id=25http://www.redhat.com/support/errata/RHSA-2008-0584.htmlhttp://www.securityfocus.com/archive/1/493682http://www.securityfocus.com/archive/1/495165/100/0/threadedhttp://www.securityfocus.com/archive/1/495818/100/0/threadedhttp://www.securityfocus.com/bid/29956http://www.securitytracker.com/id?1020451http://www.ubuntu.com/usn/USN-675-1http://www.ubuntu.com/usn/USN-675-2http://www.vupen.com/english/advisories/2008/2032/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-054https://bugzilla.redhat.com/show_bug.cgi?id=453764https://exchange.xforce.ibmcloud.com/vulnerabilities/44774https://issues.rpath.com/browse/RPL-2647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11695https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17972http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msn/slplink.chttp://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msnp9/slplink.chttp://secunia.com/advisories/30971http://secunia.com/advisories/31016http://secunia.com/advisories/31105http://secunia.com/advisories/31387http://secunia.com/advisories/31642http://secunia.com/advisories/32859http://secunia.com/advisories/32861http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0246http://www.debian.org/security/2008/dsa-1610http://www.mandriva.com/security/advisories?name=MDVSA-2008:143http://www.mandriva.com/security/advisories?name=MDVSA-2009:127http://www.openwall.com/lists/oss-security/2008/07/03/6http://www.openwall.com/lists/oss-security/2008/07/04/1http://www.pidgin.im/news/security/?id=25http://www.redhat.com/support/errata/RHSA-2008-0584.htmlhttp://www.securityfocus.com/archive/1/493682http://www.securityfocus.com/archive/1/495165/100/0/threadedhttp://www.securityfocus.com/archive/1/495818/100/0/threadedhttp://www.securityfocus.com/bid/29956http://www.securitytracker.com/id?1020451http://www.ubuntu.com/usn/USN-675-1http://www.ubuntu.com/usn/USN-675-2http://www.vupen.com/english/advisories/2008/2032/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-054https://bugzilla.redhat.com/show_bug.cgi?id=453764https://exchange.xforce.ibmcloud.com/vulnerabilities/44774https://issues.rpath.com/browse/RPL-2647https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11695https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17972
2008-07-07
Published