CVE-2010-0420
published 2010-02-24CVE-2010-0420: libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.88%
85.3th percentile
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.6.6-1 (bookworm) | pidgin 2.6.6-1 (bookworm) |
| pidgin | pidgin | <= 2.6.5 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2010-02-22·CVSS 5.0
CVE-2010-0423 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
Fabian Yamaguchi discovered that Pidgin incorrectly validated all fields of
an incoming message in the MSN protocol handler. A remote attacker could
send a specially crafted message and cause Pidgin to crash, leading to a
denial of service. (CVE-2010-0277)
Sadrul Habib Chowdhury discovered that Pidgin incorrectly handled certain
nicknames in Finch group chat rooms. A remote attacker could use a
specially crafted nickname and cause Pidgin to crash, leading to a denial
of service. (CVE-2010-0420)
Antti Hayrynen discovered that Pidgin incorrectly handled large numbers of
smileys. A remote attacker could send a specially crafted message and cause
Pidgin to become unresponsive, leading to a denial of service.
(CVE-2010-0423)
Ins
Red Hat
pidgin: Finch XMPP MUC Crash
vendor_redhat·2010-02-18·CVSS 4.3
CVE-2010-0420 [MEDIUM] pidgin: Finch XMPP MUC Crash
pidgin: Finch XMPP MUC Crash
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
Debian
CVE-2010-0420: pidgin - libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) ro...
vendor_debian·2010·CVSS 4.3
CVE-2010-0420 [MEDIUM] CVE-2010-0420: pidgin - libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) ro...
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
Scope: local
bookworm: resolved (fixed in 2.6.6-1)
bullseye: resolved (fixed in 2.6.6-1)
forky: resolved (fixed in 2.6.6-1)
sid: resolved (fixed in 2.6.6-1)
trixie: resolved (fixed in 2.6.6-1)
GHSA
GHSA-r3rc-v556-7p45: libpurple in Finch in Pidgin before 2
ghsa_unreviewed·2022-05-02
CVE-2010-0420 [MEDIUM] CWE-20 GHSA-r3rc-v556-7p45: libpurple in Finch in Pidgin before 2
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
OSV
CVE-2010-0420: libpurple in Finch in Pidgin before 2
osv·2010-02-24·CVSS 4.3
CVE-2010-0420 [MEDIUM] CVE-2010-0420: libpurple in Finch in Pidgin before 2
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.
No detection rules found.
Bugzilla
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
bugzilla·2010-02-18·CVSS 5.0
CVE-2010-0277 [MEDIUM] CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #554335:
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bug #565786:
CVE-2010-0420 pidgin: Finch XMPP MUC Crash
bug #565792:
CVE-2010-0423 pidgin: Smiley Denial of Service
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission l
Bugzilla
CVE-2010-0420 pidgin: Finch XMPP MUC Crash
bugzilla·2010-02-16·CVSS 4.3
CVE-2010-0420 [MEDIUM] CVE-2010-0420 pidgin: Finch XMPP MUC Crash
CVE-2010-0420 pidgin: Finch XMPP MUC Crash
Pidgin 2.6.6 is fixing a remote crash bug in Finch (text-based client using libpurple). If someone changes nick to '' in XMPP MUC (multi-user chat), it causes Finch to crash.
Acknowledgements:
Red Hat would like to thank Sadrul Habib Chowdhury of the Pidgin project for responsibly reporting this issue.
Discussion:
Created attachment 394492
Upstream patch to be included in 2.6.6
Additionally, following patch changes unescaping of in libpurple:
http://developer.pidgin.im/viewmtn/revision/info/0085c32abf29d034d30feef1ffb1d483e316a9a8
http://developer.pidgin.im/ticket/11318
---
Public now via:
http://pidgin.im/news/security/
---
http://pidgin.im/news/security/?id=44
---
This issue has been addressed in following products:
Red Hat Enterpr
http://developer.pidgin.im/wiki/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=44http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/39509http://www.debian.org/security/2010/dsa-2038http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.osvdb.org/62439http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/0914http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=565786https://exchange.xforce.ibmcloud.com/vulnerabilities/56399https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11485https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18230https://rhn.redhat.com/errata/RHSA-2010-0115.htmlhttp://developer.pidgin.im/wiki/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=44http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/39509http://www.debian.org/security/2010/dsa-2038http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.osvdb.org/62439http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/0914http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=565786https://exchange.xforce.ibmcloud.com/vulnerabilities/56399https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11485https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18230https://rhn.redhat.com/errata/RHSA-2010-0115.html
2010-02-24
Published