CVE-2009-1889
published 2009-07-01CVE-2009-1889: The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.38%
87.5th percentile
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.5.8-1 (bookworm) | pidgin 2.5.8-1 (bookworm) |
| pidgin | pidgin | <= 2.5.7 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.5.8-1 | 2.5.8-1 |
| pidgin | pidgin | >= 0 < 2.5.8-1 | 2.5.8-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerability
vendor_ubuntu·2009-07-06
CVE-2009-1889 Pidgin vulnerability
Title: Pidgin vulnerability
Summary: Pidgin vulnerability
Yuriy Kaminskiy discovered that Pidgin did not properly handle certain
messages in the ICQ protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash.
Instructions: After a standard system upgrade you need to restart Pidgin to effect
the necessary changes.
Red Hat
pidgin: DoS via specially-crafted ICQWebMessage
vendor_redhat·2009-05-28·CVSS 5.0
CVE-2009-1889 [MEDIUM] pidgin: DoS via specially-crafted ICQWebMessage
pidgin: DoS via specially-crafted ICQWebMessage
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
Debian
CVE-2009-1889: pidgin - The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWe...
vendor_debian·2009·CVSS 5.0
CVE-2009-1889 [MEDIUM] CVE-2009-1889: pidgin - The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWe...
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
Scope: local
bookworm: resolved (fixed in 2.5.8-1)
bullseye: resolved (fixed in 2.5.8-1)
forky: resolved (fixed in 2.5.8-1)
sid: resolved (fixed in 2.5.8-1)
trixie: resolved (fixed in 2.5.8-1)
GHSA
GHSA-2pp9-7rv9-4rpg: The OSCAR protocol implementation in Pidgin before 2
ghsa_unreviewed·2022-05-02
CVE-2009-1889 [MEDIUM] GHSA-2pp9-7rv9-4rpg: The OSCAR protocol implementation in Pidgin before 2
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
OSV
CVE-2009-1889: The OSCAR protocol implementation in Pidgin before 2
osv·2009-07-01·CVSS 5.0
CVE-2009-1889 [MEDIUM] CVE-2009-1889: The OSCAR protocol implementation in Pidgin before 2
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
No detection rules found.
No public exploits indexed.
http://developer.pidgin.im/ticket/9483http://pidgin.im/pipermail/devel/2009-May/008227.htmlhttp://secunia.com/advisories/35693http://secunia.com/advisories/35697http://secunia.com/advisories/35706http://secunia.com/advisories/37071http://www.redhat.com/support/errata/RHSA-2009-1139.htmlhttp://www.securityfocus.com/bid/35530http://www.ubuntu.com/usn/USN-796-1http://www.vupen.com/english/advisories/2009/1749https://bugzilla.redhat.com/show_bug.cgi?id=508738https://exchange.xforce.ibmcloud.com/vulnerabilities/51448https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10004https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00176.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00228.htmlhttp://developer.pidgin.im/ticket/9483http://pidgin.im/pipermail/devel/2009-May/008227.htmlhttp://secunia.com/advisories/35693http://secunia.com/advisories/35697http://secunia.com/advisories/35706http://secunia.com/advisories/37071http://www.redhat.com/support/errata/RHSA-2009-1139.htmlhttp://www.securityfocus.com/bid/35530http://www.ubuntu.com/usn/USN-796-1http://www.vupen.com/english/advisories/2009/1749https://bugzilla.redhat.com/show_bug.cgi?id=508738https://exchange.xforce.ibmcloud.com/vulnerabilities/51448https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10004https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00176.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00228.html
2009-07-01
Published