CVE-2010-3711
published 2010-10-28CVE-2010-3711: libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.27%
87.0th percentile
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.7.4-1 (bookworm) | pidgin 2.7.4-1 (bookworm) |
| pidgin | pidgin | <= 2.7.3 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2010-11-04·CVSS 5.0
CVE-2010-1624 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Pierre Noguès discovered that Pidgin incorrectly handled malformed SLP
messages in the MSN protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading to a denial
of service. This issue only affected Ubuntu 8.04 LTS, 9.10 and 10.04 LTS.
(CVE-2010-1624)
Daniel Atallah discovered that Pidgin incorrectly handled the return code
of the Base64 decoding function. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service.
(CVE-2010-3711)
Instructions: After a standard system update you need to restart Pidgin to make all the
necessary changes.
Red Hat
(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
vendor_redhat·2010-10-20·CVSS 4.0
CVE-2010-3711 [MEDIUM] (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
(libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
Debian
CVE-2010-3711: pidgin - libpurple in Pidgin before 2.7.4 does not properly validate the return value of ...
vendor_debian·2010·CVSS 4.0
CVE-2010-3711 [MEDIUM] CVE-2010-3711: pidgin - libpurple in Pidgin before 2.7.4 does not properly validate the return value of ...
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
Scope: local
bookworm: resolved (fixed in 2.7.4-1)
bullseye: resolved (fixed in 2.7.4-1)
forky: resolved (fixed in 2.7.4-1)
sid: resolved (fixed in 2.7.4-1)
trixie: resolved (fixed in 2.7.4-1)
GHSA
GHSA-hc55-4m8w-x8c2: libpurple in Pidgin before 2
ghsa_unreviewed·2022-05-17
CVE-2010-3711 [MEDIUM] CWE-20 GHSA-hc55-4m8w-x8c2: libpurple in Pidgin before 2
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
OSV
CVE-2010-3711: libpurple in Pidgin before 2
osv·2010-10-28·CVSS 4.0
CVE-2010-3711 [MEDIUM] CVE-2010-3711: libpurple in Pidgin before 2
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
No detection rules found.
Bugzilla
CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values [fedora-all]
bugzilla·2010-10-21·CVSS 4.0
CVE-2010-3711 [MEDIUM] CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values [fedora-all]
CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bug
Bugzilla
CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
bugzilla·2010-10-11·CVSS 4.0
CVE-2010-3711 [MEDIUM] CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
CVE-2010-3711 Pidgin (libpurple): Multiple DoS (crash) flaws by processing of unsanitized Base64 decoder values
Pidgin did not sanitize output of Base64 decode operation prior its further
processing. A remote attacker, valid Pidgin user, could use this flaw to cause:
a, NULL pointer dereference (pidgin daemon crash) by transfering of a
specially-crafted buddy icon via the Yahoo protocol plugin
b, NULL pointer dereference (pidgin deamon crash) by providing a
specially-crafted IP address value for peer-to-peer connection
in the Yahoo protocol plugin
c, NULL pointer dereference (pidgin daemon crash) by providing a
specially-crafted transfer header in the MSN protocol plugin
d, NULL pointer dereference (pidgin daemon crash) by providing a
specially-crafted login challenge value in the MyS
http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcchttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050133.htmlhttp://pidgin.im/news/security/?id=48http://secunia.com/advisories/41893http://secunia.com/advisories/41899http://secunia.com/advisories/42075http://secunia.com/advisories/42294http://securitytracker.com/id?1024623http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462352http://www.mandriva.com/security/advisories?name=MDVSA-2010:208http://www.osvdb.org/68773http://www.redhat.com/support/errata/RHSA-2010-0788.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0890.htmlhttp://www.securityfocus.com/bid/44283http://www.ubuntu.com/usn/USN-1014-1http://www.vupen.com/english/advisories/2010/2753http://www.vupen.com/english/advisories/2010/2754http://www.vupen.com/english/advisories/2010/2755http://www.vupen.com/english/advisories/2010/2847http://www.vupen.com/english/advisories/2010/2851http://www.vupen.com/english/advisories/2010/2870https://bugzilla.redhat.com/show_bug.cgi?id=641921https://exchange.xforce.ibmcloud.com/vulnerabilities/62708https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18506http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcchttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050133.htmlhttp://pidgin.im/news/security/?id=48http://secunia.com/advisories/41893http://secunia.com/advisories/41899http://secunia.com/advisories/42075http://secunia.com/advisories/42294http://securitytracker.com/id?1024623http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462352http://www.mandriva.com/security/advisories?name=MDVSA-2010:208http://www.osvdb.org/68773http://www.redhat.com/support/errata/RHSA-2010-0788.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0890.htmlhttp://www.securityfocus.com/bid/44283http://www.ubuntu.com/usn/USN-1014-1http://www.vupen.com/english/advisories/2010/2753http://www.vupen.com/english/advisories/2010/2754http://www.vupen.com/english/advisories/2010/2755http://www.vupen.com/english/advisories/2010/2847http://www.vupen.com/english/advisories/2010/2851http://www.vupen.com/english/advisories/2010/2870https://bugzilla.redhat.com/show_bug.cgi?id=641921https://exchange.xforce.ibmcloud.com/vulnerabilities/62708https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18506
2010-10-28
Published