CVE-2011-3184
published 2011-08-29CVE-2011-3184: The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.86%
89.0th percentile
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.0-1 (bookworm) | pidgin 2.10.0-1 (bookworm) |
| pidgin | pidgin | <= 2.9.0 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fh6-vrqh-wvpv: The msn_httpconn_parse_data function in httpconn
ghsa_unreviewed·2022-05-17
CVE-2011-3184 [MEDIUM] GHSA-4fh6-vrqh-wvpv: The msn_httpconn_parse_data function in httpconn
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
OSV
CVE-2011-3184: The msn_httpconn_parse_data function in httpconn
osv·2011-08-29·CVSS 4.3
CVE-2011-3184 [MEDIUM] CVE-2011-3184: The msn_httpconn_parse_data function in httpconn
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 4.0
CVE-2011-1091 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin could be made to crash if it received specially crafted network
traffic.
Marius Wachtler discovered that Pidgin incorrectly handled malformed YMSG
messages in the Yahoo! protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading to a denial
of service. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2011-1091)
Marius Wachtler discovered that Pidgin incorrectly handled HTTP 100
responses in the MSN protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading to a denial
of service. (CVE-2011-3184)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the SILC protocol handler. A remote attacker could send
Red Hat
pidgin: Remote crash in MSN protocol plugin
vendor_redhat·2011-08-20·CVSS 4.3
CVE-2011-3184 [MEDIUM] pidgin: Remote crash in MSN protocol plugin
pidgin: Remote crash in MSN protocol plugin
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
Statement: Red Hat does not consider this to be a security flaw. As a malicious MSN server is needed, there are far worlse implications to a user connecting to an untrusted server than a DoS.
Package: pidgin (Red Hat Enterprise Linux 4) - Not affected
Package: pidgin (Red Hat Enterprise Linux 5) - Not affected
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-3184: pidgin - The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in...
vendor_debian·2011·CVSS 4.3
CVE-2011-3184 [MEDIUM] CVE-2011-3184: pidgin - The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in...
The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.
Scope: local
bookworm: resolved (fixed in 2.10.0-1)
bullseye: resolved (fixed in 2.10.0-1)
forky: resolved (fixed in 2.10.0-1)
sid: resolved (fixed in 2.10.0-1)
trixie: resolved (fixed in 2.10.0-1)
No detection rules found.
No public exploits indexed.
http://developer.pidgin.im/viewmtn/revision/diff/5c2dba4a7e2e76b76e7f472b88953a4316706d43/with/16af0661899a978b4fedc1c165965b85009013d1/libpurple/protocols/msn/httpconn.chttp://developer.pidgin.im/viewmtn/revision/info/16af0661899a978b4fedc1c165965b85009013d1http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064943.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065190.htmlhttp://pidgin.im/news/security/?id=54http://secunia.com/advisories/45663http://secunia.com/advisories/45916http://securitytracker.com/id?1025961http://www.openwall.com/lists/oss-security/2011/08/22/10http://www.openwall.com/lists/oss-security/2011/08/22/12http://www.openwall.com/lists/oss-security/2011/08/22/4http://www.openwall.com/lists/oss-security/2011/08/22/7http://www.securityfocus.com/bid/49268https://bugzilla.redhat.com/show_bug.cgi?id=732405https://exchange.xforce.ibmcloud.com/vulnerabilities/69341https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18284http://developer.pidgin.im/viewmtn/revision/diff/5c2dba4a7e2e76b76e7f472b88953a4316706d43/with/16af0661899a978b4fedc1c165965b85009013d1/libpurple/protocols/msn/httpconn.chttp://developer.pidgin.im/viewmtn/revision/info/16af0661899a978b4fedc1c165965b85009013d1http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064943.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/065190.htmlhttp://pidgin.im/news/security/?id=54http://secunia.com/advisories/45663http://secunia.com/advisories/45916http://securitytracker.com/id?1025961http://www.openwall.com/lists/oss-security/2011/08/22/10http://www.openwall.com/lists/oss-security/2011/08/22/12http://www.openwall.com/lists/oss-security/2011/08/22/4http://www.openwall.com/lists/oss-security/2011/08/22/7http://www.securityfocus.com/bid/49268https://bugzilla.redhat.com/show_bug.cgi?id=732405https://exchange.xforce.ibmcloud.com/vulnerabilities/69341https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18284
2011-08-29
Published