CVE-2010-0277
published 2010-01-09CVE-2010-0277: slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.31%
81.5th percentile
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adium | adium | — | — |
| debian | pidgin | < pidgin 2.6.6-1 (bookworm) | pidgin 2.6.6-1 (bookworm) |
| pidgin | pidgin | <= 2.6.5 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2010-02-22·CVSS 5.0
CVE-2010-0423 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
Fabian Yamaguchi discovered that Pidgin incorrectly validated all fields of
an incoming message in the MSN protocol handler. A remote attacker could
send a specially crafted message and cause Pidgin to crash, leading to a
denial of service. (CVE-2010-0277)
Sadrul Habib Chowdhury discovered that Pidgin incorrectly handled certain
nicknames in Finch group chat rooms. A remote attacker could use a
specially crafted nickname and cause Pidgin to crash, leading to a denial
of service. (CVE-2010-0420)
Antti Hayrynen discovered that Pidgin incorrectly handled large numbers of
smileys. A remote attacker could send a specially crafted message and cause
Pidgin to become unresponsive, leading to a denial of service.
(CVE-2010-0423)
Ins
Debian
CVE-2010-0277: pidgin - slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including ...
vendor_debian·2010·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277: pidgin - slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including ...
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Scope: local
bookworm: resolved (fixed in 2.6.6-1)
bullseye: resolved (fixed in 2.6.6-1)
forky: resolved (fixed in 2.6.6-1)
sid: resolved (fixed in 2.6.6-1)
trixie: resolved (fixed in 2.6.6-1)
Red Hat
pidgin MSN protocol plugin memory corruption
vendor_redhat·2009-12-27·CVSS 7.5
CVE-2010-0277 [HIGH] pidgin MSN protocol plugin memory corruption
pidgin MSN protocol plugin memory corruption
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Statement: We currently have no plans to fix this flaw in Red Hat Enterprise Linux 3 as the MSN protocol support in the provided version of Pidgin (1.5.1) is out-dated and no longer supported by MSN servers. There are no plans to backport MSN protocol changes for that version of Pidgin.
GHSA
GHSA-rj5f-77wg-8qgv: slp
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2010-0277 [HIGH] GHSA-rj5f-77wg-8qgv: slp
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
OSV
CVE-2010-0277: slp
osv·2010-01-09·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277: slp
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
No detection rules found.
Bugzilla
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
bugzilla·2010-02-18·CVSS 5.0
CVE-2010-0277 [MEDIUM] CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #554335:
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bug #565786:
CVE-2010-0420 pidgin: Finch XMPP MUC Crash
bug #565792:
CVE-2010-0423 pidgin: Smiley Denial of Service
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission l
Bugzilla
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bugzilla·2010-01-11·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277 pidgin MSN protocol plugin memory corruption
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and
Adium 1.3.8 allows remote attackers to cause a denial of service
(memory corruption) or possibly have unspecified other impact via
unknown vectors, a different issue than CVE-2010-0013.
Reference: URL:http://www.openwall.com/lists/oss-security/2010/01/07/2
Reference: MISC:http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
Discussion:
http://pidgin.im/news/security/?id=43
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0115 https://rhn.redhat.com/errata/RHSA-2010-0115.html
---
pidgin-2.6.6-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.
http://blogs.sun.com/security/entry/cve_2010_0277_malformed_msnhttp://developer.pidgin.im/wiki/ChangeLoghttp://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=43http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/41868http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.openwall.com/lists/oss-security/2010/01/07/2http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/1020http://www.vupen.com/english/advisories/2010/2693https://bugzilla.redhat.com/show_bug.cgi?id=554335https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18348https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9421https://rhn.redhat.com/errata/RHSA-2010-0115.htmlhttp://blogs.sun.com/security/entry/cve_2010_0277_malformed_msnhttp://developer.pidgin.im/wiki/ChangeLoghttp://events.ccc.de/congress/2009/Fahrplan/events/3596.en.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=43http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/41868http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.openwall.com/lists/oss-security/2010/01/07/2http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/1020http://www.vupen.com/english/advisories/2010/2693https://bugzilla.redhat.com/show_bug.cgi?id=554335https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18348https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9421https://rhn.redhat.com/errata/RHSA-2010-0115.html
2010-01-09
Published