CVE-2011-3594
published 2011-11-04CVE-2011-3594: The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.19%
86.7th percentile
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.1-1 (bookworm) | pidgin 2.10.1-1 (bookworm) |
| pidgin | libpurple | <= 2.10.0 | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
| pidgin | libpurple | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pidgin: SILC remote crash on channel messages
vendor_redhat·2011-12-11·CVSS 4.3
CVE-2011-4603 [MEDIUM] pidgin: SILC remote crash on channel messages
pidgin: SILC remote crash on channel messages
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Statement: Not vulnerable. This issue did not affect the version of pidgin as shipped with Red Hat Enterprise Linux 6 as it explicitly disables support for the SILC protocol.
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2011-11-21·CVSS 4.0
CVE-2011-1091 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Pidgin could be made to crash if it received specially crafted network
traffic.
Marius Wachtler discovered that Pidgin incorrectly handled malformed YMSG
messages in the Yahoo! protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading to a denial
of service. This issue only affected Ubuntu 10.04 LTS and 10.10.
(CVE-2011-1091)
Marius Wachtler discovered that Pidgin incorrectly handled HTTP 100
responses in the MSN protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading to a denial
of service. (CVE-2011-3184)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the SILC protocol handler. A remote attacker could send
Red Hat
libpurple: invalid UTF-8 string handling in SILC messages
vendor_redhat·2011-09-29·CVSS 4.3
CVE-2011-3594 [MEDIUM] libpurple: invalid UTF-8 string handling in SILC messages
libpurple: invalid UTF-8 string handling in SILC messages
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
Statement: Not vulnerable. This issue did not affect the version of pidgin as shipped with Red Hat Enterprise Linux 6 as it explicitly disables support for the SILC protocol.
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-4603: pidgin - The silc_channel_message function in ops.c in the SILC protocol plugin in libpur...
vendor_debian·2011·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603: pidgin - The silc_channel_message function in ops.c in the SILC protocol plugin in libpur...
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Scope: local
bookworm: resolved (fixed in 2.10.1-1)
bullseye: resolved (fixed in 2.10.1-1)
forky: resolved (fixed in 2.10.1-1)
sid: resolved (fixed in 2.10.1-1)
trixie: resolved (fixed in 2.10.1-1)
Debian
CVE-2011-3594: pidgin - The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10...
vendor_debian·2011·CVSS 4.3
CVE-2011-3594 [MEDIUM] CVE-2011-3594: pidgin - The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10...
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
Scope: local
bookworm: resolved (fixed in 2.10.1-1)
bullseye: resolved (fixed in 2.10.1-1)
forky: resolved (fixed in 2.10.1-1)
sid: resolved (fixed in 2.10.1-1)
trixie: resolved (fixed in 2.10.1-1)
GHSA
GHSA-6f79-g335-f9mf: The silc_channel_message function in ops
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-4603 [MEDIUM] CWE-20 GHSA-6f79-g335-f9mf: The silc_channel_message function in ops
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
GHSA
GHSA-5qw6-gghj-96qh: The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2
ghsa_unreviewed·2022-05-17
CVE-2011-3594 [MEDIUM] CWE-119 GHSA-5qw6-gghj-96qh: The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
OSV
CVE-2011-4603: The silc_channel_message function in ops
osv·2011-12-17·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603: The silc_channel_message function in ops
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
OSV
CVE-2011-3594: The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2
osv·2011-11-04·CVSS 4.3
CVE-2011-3594 [MEDIUM] CVE-2011-3594: The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2
The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4603 pidgin: SILC remote crash on channel messages
bugzilla·2011-12-12·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603 pidgin: SILC remote crash on channel messages
CVE-2011-4603 pidgin: SILC remote crash on channel messages
When receiving various incoming messages, the SILC protocol plugin failed to validate that a piece of text was UTF-8. In some cases invalid UTF-8 data would lead to a crash. This vulnerability is similar to CVE-2011-3594, but occurs in a different piece of code and was fixed at a later date.
Reference:
http://pidgin.im/news/security/?id=59
Patch: http://developer.pidgin.im/viewmtn/revision/info/afb9ede3de989f217f03d5670cca00e628bd11f1
Discussion:
Created pidgin tracking bugs for this issue
Affects: fedora-all [bug 766454]
---
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Diego Bauche Madero from IOActive as the original reporter.
---
This issue has been a
Bugzilla
CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages [fedora-all]
bugzilla·2011-10-05·CVSS 4.3
CVE-2011-3594 [MEDIUM] CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages [fedora-all]
CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=743481
Please note: this issue affect
Bugzilla
CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages
bugzilla·2011-10-05·CVSS 4.3
CVE-2011-3594 [MEDIUM] CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages
CVE-2011-3594 libpurple: invalid UTF-8 string handling in SILC messages
A flaw was reported [1] in libpurple's SILC protocol plugin, and all software which uses SILC via libpurple. The g_markup_escape_text() function, when called on strings that have not been verified as valid UTF-8, will read past the end of the string and eventually segfault for certain sequences in some versions of Glib2. The behaviour of this function was undefined, and because it depends on the particular version of Glib2 in use, it is unknown what the complete ramifications of the flaw is, however it has been verified that an untrusted user could remotely crash a libpurple client via specially crafted SILC messages.
This flaw is believed to affect all versions of libpurple up to and including 2.10.0. This has been
http://developer.pidgin.im/ticket/14636http://developer.pidgin.im/viewmtn/revision/diff/be5e66abad2af29604bc794cc4c6600ab12751f3/with/7eb1f6d56cc58bbb5b56b7df53955d36b9b419b8http://pidgin.im/news/security/?id=56http://secunia.com/advisories/46376http://www.mandriva.com/security/advisories?name=MDVSA-2011:183http://www.redhat.com/support/errata/RHSA-2011-1371.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=743481https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18034http://developer.pidgin.im/ticket/14636http://developer.pidgin.im/viewmtn/revision/diff/be5e66abad2af29604bc794cc4c6600ab12751f3/with/7eb1f6d56cc58bbb5b56b7df53955d36b9b419b8http://pidgin.im/news/security/?id=56http://secunia.com/advisories/46376http://www.mandriva.com/security/advisories?name=MDVSA-2011:183http://www.redhat.com/support/errata/RHSA-2011-1371.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=743481https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18034
2011-11-04
Published