CVE-2010-0423
published 2010-02-24CVE-2010-0423: gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1)…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.31%
81.6th percentile
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.6.6-1 (bookworm) | pidgin 2.6.6-1 (bookworm) |
| pidgin | pidgin | <= 2.6.5 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-755g-9f69-83cm: gtkimhtml
ghsa_unreviewed·2022-05-02
CVE-2010-0423 [MEDIUM] GHSA-755g-9f69-83cm: gtkimhtml
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
OSV
CVE-2010-0423: gtkimhtml
osv·2010-02-24·CVSS 5.0
CVE-2010-0423 [MEDIUM] CVE-2010-0423: gtkimhtml
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2010-02-22·CVSS 5.0
CVE-2010-0423 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin vulnerabilities
Fabian Yamaguchi discovered that Pidgin incorrectly validated all fields of
an incoming message in the MSN protocol handler. A remote attacker could
send a specially crafted message and cause Pidgin to crash, leading to a
denial of service. (CVE-2010-0277)
Sadrul Habib Chowdhury discovered that Pidgin incorrectly handled certain
nicknames in Finch group chat rooms. A remote attacker could use a
specially crafted nickname and cause Pidgin to crash, leading to a denial
of service. (CVE-2010-0420)
Antti Hayrynen discovered that Pidgin incorrectly handled large numbers of
smileys. A remote attacker could send a specially crafted message and cause
Pidgin to become unresponsive, leading to a denial of service.
(CVE-2010-0423)
Ins
Red Hat
pidgin: Smiley Denial of Service
vendor_redhat·2010-02-18·CVSS 5.0
CVE-2010-0423 [MEDIUM] pidgin: Smiley Denial of Service
pidgin: Smiley Denial of Service
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
Statement: We currently have no plans to fix this flaw in Red Hat Enterprise Linux 3 as the issue only causes Pidgin client to become unresponsive or crash.
Debian
CVE-2010-0423: pidgin - gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of ...
vendor_debian·2010·CVSS 5.0
CVE-2010-0423 [MEDIUM] CVE-2010-0423: pidgin - gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of ...
gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.
Scope: local
bookworm: resolved (fixed in 2.6.6-1)
bullseye: resolved (fixed in 2.6.6-1)
forky: resolved (fixed in 2.6.6-1)
sid: resolved (fixed in 2.6.6-1)
trixie: resolved (fixed in 2.6.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
bugzilla·2010-02-18·CVSS 5.0
CVE-2010-0277 [MEDIUM] CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 Multiple pidgin vulnerabilities [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #554335:
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bug #565786:
CVE-2010-0420 pidgin: Finch XMPP MUC Crash
bug #565792:
CVE-2010-0423 pidgin: Smiley Denial of Service
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission l
Bugzilla
CVE-2010-0423 pidgin: Smiley Denial of Service
bugzilla·2010-02-16·CVSS 5.0
CVE-2010-0423 [MEDIUM] CVE-2010-0423 pidgin: Smiley Denial of Service
CVE-2010-0423 pidgin: Smiley Denial of Service
Pidgin 2.6.6 is fixing a denial of service (remotely-triggered high CPU use) triggered by large amount of "smileys" in received instant messages. This issue is addressed by setting a limit on number of smileys processed.
Discussion:
Created attachment 394494
Upstream patch to be included in 2.6.6
---
Public now via:
http://pidgin.im/news/security/
---
http://pidgin.im/news/security/?id=45
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0115 https://rhn.redhat.com/errata/RHSA-2010-0115.html
---
pidgin-2.6.6-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
---
pidgin-2.6.6-1.f
http://developer.pidgin.im/wiki/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=45http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/39509http://www.debian.org/security/2010/dsa-2038http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.osvdb.org/62440http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/0914http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=565792https://exchange.xforce.ibmcloud.com/vulnerabilities/56394https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17554https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9842https://rhn.redhat.com/errata/RHSA-2010-0115.htmlhttp://developer.pidgin.im/wiki/ChangeLoghttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pidgin.im/news/security/?id=45http://secunia.com/advisories/38563http://secunia.com/advisories/38640http://secunia.com/advisories/38658http://secunia.com/advisories/38712http://secunia.com/advisories/38915http://secunia.com/advisories/39509http://www.debian.org/security/2010/dsa-2038http://www.mandriva.com/security/advisories?name=MDVSA-2010:041http://www.mandriva.com/security/advisories?name=MDVSA-2010:085http://www.osvdb.org/62440http://www.securityfocus.com/bid/38294http://www.ubuntu.com/usn/USN-902-1http://www.vupen.com/english/advisories/2010/0413http://www.vupen.com/english/advisories/2010/0914http://www.vupen.com/english/advisories/2010/1020https://bugzilla.redhat.com/show_bug.cgi?id=565792https://exchange.xforce.ibmcloud.com/vulnerabilities/56394https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17554https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9842https://rhn.redhat.com/errata/RHSA-2010-0115.html
2010-02-24
Published