CVE-2009-1373
published 2009-05-26CVE-2009-1373: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via…
PriorityP431high7.1CVSS 2.0
AVNACHAuSCCICAC
EPSS
4.27%
90.0th percentile
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.5.6-1 (bookworm) | pidgin 2.5.6-1 (bookworm) |
| pidgin | pidgin | <= 2.5.5 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.5.6-1 | 2.5.6-1 |
| pidgin | pidgin | >= 0 < 2.5.6-1 | 2.5.6-1 |
| pidgin | pidgin | >= 0 < 2.5.6-1 | 2.5.6-1 |
| pidgin | pidgin | >= 0 < 2.5.6-1 | 2.5.6-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2009-06-03·CVSS 7.1
CVE-2009-1373 [HIGH] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
It was discovered that Pidgin did not properly handle certain malformed
messages when sending a file using the XMPP protocol handler. If a user
were tricked into sending a file, a remote attacker could send a specially
crafted response and cause Pidgin to crash, or possibly execute arbitrary
code with user privileges. (CVE-2009-1373)
It was discovered that Pidgin did not properly handle certain malformed
messages in the QQ protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash. This issue only
affected Ubuntu 8.10 and 9.04. (CVE-2009-1374)
It was discovered that Pidgin did not properly handle certain malformed
messages in the XMPP and Sametime protocol handlers. A remote attacker
Ubuntu
Gaim vulnerabilities
vendor_ubuntu·2009-06-03·CVSS 7.1
CVE-2009-1373 [HIGH] Gaim vulnerabilities
Title: Gaim vulnerabilities
Summary: Gaim vulnerabilities
It was discovered that Gaim did not properly handle certain malformed
messages when sending a file using the XMPP protocol handler. If a user
were tricked into sending a file, a remote attacker could send a specially
crafted response and cause Gaim to crash, or possibly execute arbitrary
code with user privileges. (CVE-2009-1373)
It was discovered that Gaim did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a
specially crafted message and possibly execute arbitrary code with user
privileges. (CVE-2009-1376)
Instructions: After a standard system upgrade you need to restart Gaim to effect
the necessary changes.
Red Hat
pidgin file transfer buffer overflow
vendor_redhat·2009-05-02·CVSS 7.1
CVE-2009-1373 [HIGH] pidgin file transfer buffer overflow
pidgin file transfer buffer overflow
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-1373: pidgin - Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) b...
vendor_debian·2009·CVSS 7.1
CVE-2009-1373 [HIGH] CVE-2009-1373: pidgin - Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) b...
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 2.5.6-1)
bullseye: resolved (fixed in 2.5.6-1)
forky: resolved (fixed in 2.5.6-1)
sid: resolved (fixed in 2.5.6-1)
trixie: resolved (fixed in 2.5.6-1)
GHSA
GHSA-hfwm-9244-px83: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1373 [HIGH] CWE-119 GHSA-hfwm-9244-px83: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.
OSV
CVE-2009-1373: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2
osv·2009-05-26·CVSS 7.1
CVE-2009-1373 [HIGH] CVE-2009-1373: Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
bugzilla·2009-05-26·CVSS 6.8
CVE-2009-1376 [MEDIUM] CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
CVE-2009-1376 CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 Multiple pidgin vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #500493: CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927
bug #500488: CVE-2009-1373 pidgin file transfer buffer overflow
bug #500490: CVE-2009-1374 pidgin DoS when decrypting qq packets
bug #500491: CVE-2009-1375 pidgin PurpleCircBuffer corruption
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE
Bugzilla
CVE-2009-1373 pidgin file transfer buffer overflow
bugzilla·2009-05-12·CVSS 7.1
CVE-2009-1373 [HIGH] CVE-2009-1373 pidgin file transfer buffer overflow
CVE-2009-1373 pidgin file transfer buffer overflow
A buffer overflow flaw was found in the way Pidgin initiates file
transfers. If a Pidgin client initiates a file transfer, and the remote
target sends a malformed response, it triggers a buffer overflow.
Discussion:
This flaw only affects the Jabber protocol.
---
Link to upstream advisory:
http://www.pidgin.im/news/security//?id=29
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Via RHSA-2009:1059 https://rhn.redhat.com/errata/RHSA-2009-1059.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Via RHSA-2009:1059 https://rhn.redhat.com/errata/RHSA-2009-1059.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat
http://debian.org/security/2009/dsa-1805http://secunia.com/advisories/35188http://secunia.com/advisories/35194http://secunia.com/advisories/35202http://secunia.com/advisories/35215http://secunia.com/advisories/35294http://secunia.com/advisories/35329http://secunia.com/advisories/35330http://www.gentoo.org/security/en/glsa/glsa-200905-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:140http://www.mandriva.com/security/advisories?name=MDVSA-2009:173http://www.pidgin.im/news/security/?id=29http://www.redhat.com/support/errata/RHSA-2009-1059.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1060.htmlhttp://www.securityfocus.com/bid/35067http://www.ubuntu.com/usn/USN-781-1http://www.ubuntu.com/usn/USN-781-2http://www.vupen.com/english/advisories/2009/1396https://bugzilla.redhat.com/show_bug.cgi?id=500488https://exchange.xforce.ibmcloud.com/vulnerabilities/50682https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17722https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9005https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.htmlhttp://debian.org/security/2009/dsa-1805http://secunia.com/advisories/35188http://secunia.com/advisories/35194http://secunia.com/advisories/35202http://secunia.com/advisories/35215http://secunia.com/advisories/35294http://secunia.com/advisories/35329http://secunia.com/advisories/35330http://www.gentoo.org/security/en/glsa/glsa-200905-07.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:140http://www.mandriva.com/security/advisories?name=MDVSA-2009:173http://www.pidgin.im/news/security/?id=29http://www.redhat.com/support/errata/RHSA-2009-1059.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1060.htmlhttp://www.securityfocus.com/bid/35067http://www.ubuntu.com/usn/USN-781-1http://www.ubuntu.com/usn/USN-781-2http://www.vupen.com/english/advisories/2009/1396https://bugzilla.redhat.com/show_bug.cgi?id=500488https://exchange.xforce.ibmcloud.com/vulnerabilities/50682https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17722https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9005https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html
2009-05-26
Published