CVE-2010-0013
published 2010-01-09CVE-2010-0013: Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
12.50%
95.8th percentile
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adium | adium | — | — |
| debian | pidgin | < pidgin 2.6.6-1 (bookworm) | pidgin 2.6.6-1 (bookworm) |
| debian | pidgin | < pidgin 2.6.5-1 (bookworm) | pidgin 2.6.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | 11.0 – 11.2 | — |
| pidgin | pidgin | <= 2.6.5 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2010-01-18·CVSS 5.0
CVE-2008-2955 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
It was discovered that Pidgin did not properly handle certain topic
messages in the IRC protocol handler. If a user were tricked into
connecting to a malicious IRC server, an attacker could cause Pidgin to
crash, leading to a denial of service. This issue only affected Ubuntu 8.04
LTS, Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-2703)
It was discovered that Pidgin did not properly enforce the "require
TLS/SSL" setting when connecting to certain older Jabber servers. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. This issue only affected
Ubuntu 8.04 LTS, Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-3026)
It was discovered that Pidgin did not properly
Debian
CVE-2010-0277: pidgin - slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including ...
vendor_debian·2010·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277: pidgin - slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including ...
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Scope: local
bookworm: resolved (fixed in 2.6.6-1)
bullseye: resolved (fixed in 2.6.6-1)
forky: resolved (fixed in 2.6.6-1)
sid: resolved (fixed in 2.6.6-1)
trixie: resolved (fixed in 2.6.6-1)
Debian
CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...
vendor_debian·2010·CVSS 5.0
CVE-2010-0013 [MEDIUM] CVE-2010-0013: pidgin - Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurp...
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
Scope: local
bookworm: resolved (fixed in 2.6.5-1)
bullseye: resolved (fixed in 2.6.5-1)
forky: resolved (fixed in 2.6.5-1)
sid: resolved (fixed in 2.6.5-1)
trixie: resolved (fixed in 2.6.5-1)
Red Hat
pidgin MSN protocol plugin memory corruption
vendor_redhat·2009-12-27·CVSS 7.5
CVE-2010-0277 [HIGH] pidgin MSN protocol plugin memory corruption
pidgin MSN protocol plugin memory corruption
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Statement: We currently have no plans to fix this flaw in Red Hat Enterprise Linux 3 as the MSN protocol support in the provided version of Pidgin (1.5.1) is out-dated and no longer supported by MSN servers. There are no plans to backport MSN protocol changes for that version of Pidgin.
Red Hat
pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
vendor_redhat·2009-12-27·CVSS 5.0
CVE-2010-0013 [MEDIUM] pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
GHSA
GHSA-rj5f-77wg-8qgv: slp
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2010-0277 [HIGH] GHSA-rj5f-77wg-8qgv: slp
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
GHSA
GHSA-v6ph-x2c7-6g37: Directory traversal vulnerability in slp
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2010-0013 [MEDIUM] CWE-22 GHSA-v6ph-x2c7-6g37: Directory traversal vulnerability in slp
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
OSV
CVE-2010-0013: Directory traversal vulnerability in slp
osv·2010-01-09·CVSS 5.0
CVE-2010-0013 [MEDIUM] CVE-2010-0013: Directory traversal vulnerability in slp
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.
OSV
CVE-2010-0277: slp
osv·2010-01-09·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277: slp
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Suricata
GPL SNMP public access tcp
suricata·2010-09-23
CVE-1999-0517 GPL SNMP public access tcp
GPL SNMP public access tcp
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"GPL SNMP public access tcp"; flow:established,to_server; content:"public"; reference:bugtraq,2112; reference:bugtraq,4088; reference:bugtraq,4089; reference:bugtraq,7212; reference:cve,1999-0517; reference:cve,2002-0012; reference:cve,2002-0013; classtype:attempted-recon; sid:2101412; rev:15; metadata:created_at 2010_09_23, cve CVE_1999_0517, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL SNMP private access tcp
suricata·2010-09-23
CVE-2002-0012 GPL SNMP private access tcp
GPL SNMP private access tcp
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"GPL SNMP private access tcp"; flow:established,to_server; content:"private"; reference:bugtraq,4088; reference:bugtraq,4089; reference:bugtraq,4132; reference:cve,2002-0012; reference:cve,2002-0013; classtype:attempted-recon; sid:2101414; rev:13; metadata:created_at 2010_09_23, cve CVE_2002_0012, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL SNMP public access udp
suricata·2010-09-23
CVE-1999-0517 GPL SNMP public access udp
GPL SNMP public access udp
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"GPL SNMP public access udp"; content:"public"; fast_pattern; reference:bugtraq,2112; reference:bugtraq,4088; reference:bugtraq,4089; reference:cve,1999-0517; reference:cve,2002-0012; reference:cve,2002-0013; classtype:attempted-recon; sid:2101411; rev:13; metadata:created_at 2010_09_23, cve CVE_1999_0517, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
GPL SNMP private access udp
suricata·2010-09-23
CVE-2002-0012 GPL SNMP private access udp
GPL SNMP private access udp
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"GPL SNMP private access udp"; content:"private"; fast_pattern; reference:bugtraq,4088; reference:bugtraq,4089; reference:bugtraq,4132; reference:bugtraq,7212; reference:cve,2002-0012; reference:cve,2002-0013; classtype:attempted-recon; sid:2101413; rev:12; metadata:created_at 2010_09_23, cve CVE_2002_0012, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Bugzilla
CVE-2011-0013 CVE-2010-3718 tomcat5 various flaws [fedora-all]
bugzilla·2011-02-07·CVSS 1.2
CVE-2011-0013 [LOW] CVE-2011-0013 CVE-2010-3718 tomcat5 various flaws [fedora-all]
CVE-2011-0013 CVE-2010-3718 tomcat5 various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=675786
Please note: this issue affects multiple supported v
Bugzilla
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bugzilla·2010-01-11·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277 pidgin MSN protocol plugin memory corruption
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and
Adium 1.3.8 allows remote attackers to cause a denial of service
(memory corruption) or possibly have unspecified other impact via
unknown vectors, a different issue than CVE-2010-0013.
Reference: URL:http://www.openwall.com/lists/oss-security/2010/01/07/2
Reference: MISC:http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
Discussion:
http://pidgin.im/news/security/?id=43
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0115 https://rhn.redhat.com/errata/RHSA-2010-0115.html
---
pidgin-2.6.6-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.
Bugzilla
CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
bugzilla·2010-01-05·CVSS 7.5
CVE-2010-0013 [HIGH] CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
On 26C3, Fabian Yamaguchi presented a directory traversal flaw in libpurple MSN protocol implementation. The flaw can be used by the remote attacker to download arbitrary file readable by the user running instant messenger using libpurple (such as pidgin) from the victim's computer via MSN emoticon / smiley download request. More details in Fabian's presentation:
http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
http://events.ccc.de/congress/2009/Fahrplan/attachments/1483_26c3_ipv4_fuckups.pdf
(slides 10-22)
Upstream fix:
http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810
which depends on the other two commits:
http://d.pidgin.im/viewmtn/revision/in
http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92fhttp://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.chttp://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://secunia.com/advisories/37953http://secunia.com/advisories/37954http://secunia.com/advisories/37961http://secunia.com/advisories/38915http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.openwall.com/lists/oss-security/2010/01/02/1http://www.openwall.com/lists/oss-security/2010/01/07/1http://www.openwall.com/lists/oss-security/2010/01/07/2http://www.vupen.com/english/advisories/2009/3662http://www.vupen.com/english/advisories/2009/3663http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=552483https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17620http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92fhttp://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.chttp://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://secunia.com/advisories/37953http://secunia.com/advisories/37954http://secunia.com/advisories/37961http://secunia.com/advisories/38915http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.openwall.com/lists/oss-security/2010/01/02/1http://www.openwall.com/lists/oss-security/2010/01/07/1http://www.openwall.com/lists/oss-security/2010/01/07/2http://www.vupen.com/english/advisories/2009/3662http://www.vupen.com/english/advisories/2009/3663http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=552483https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17620
2010-01-09
Published