CVE-2011-4601
published 2011-12-25CVE-2011-4601: family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.70%
90.8th percentile
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.1-1 (bookworm) | pidgin 2.10.1-1 (bookworm) |
| pidgin | pidgin | <= 2.10.0 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j8rm-cj64-mfw6: family_feedbag
ghsa_unreviewed·2022-05-17
CVE-2011-4601 [MEDIUM] CWE-20 GHSA-j8rm-cj64-mfw6: family_feedbag
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
OSV
CVE-2011-4601: family_feedbag
osv·2011-12-25·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601: family_feedbag
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
(libpurple): Invalid UTF-8 string handling in OSCAR messages
vendor_redhat·2011-12-10·CVSS 5.0
CVE-2011-4601 [MEDIUM] (libpurple): Invalid UTF-8 string handling in OSCAR messages
(libpurple): Invalid UTF-8 string handling in OSCAR messages
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
Debian
CVE-2011-4601: pidgin - family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10...
vendor_debian·2011·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601: pidgin - family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10...
family_feedbag.c in the oscar protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted (1) AIM or (2) ICQ message associated with buddy-list addition.
Scope: local
bookworm: resolved (fixed in 2.10.1-1)
bullseye: resolved (fixed in 2.10.1-1)
forky: resolved (fixed in 2.10.1-1)
sid: resolved (fixed in 2.10.1-1)
trixie: resolved (fixed in 2.10.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
bugzilla·2011-12-12·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
bugzilla·2011-12-08·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
An out-of heap-based buffer read flaw was found in the way OSCAR (Open System for CommunicAtion in Realtime) protocol plug-in of Pidgin, a Gtk+ based multiprotocol instant messaging client, processed authorization denied messages, containing non-UTF-8 sequences. If a rogue server sent a specially-crafted authorization denied message, it could lead to denial of service (Pidgin crash).
Reference:
http://pidgin.im/news/security/?id=57
Patch: http://developer.pidgin.im/viewmtn/revision/info/757272a78a8ca6027d518e614712c3399e34dda3
Discussion:
This issue affects the versions of the pidgin package, as shipped with Red Hat Enterprise Linux 4, 5, and 6.
--
This issue affects the versions of the pidgin package,
http://developer.pidgin.im/viewmtn/revision/diff/bc79b1bf09dcfa1d8edac86a06761fce7416e69c/with/757272a78a8ca6027d518e614712c3399e34dda3/libpurple/protocols/oscar/family_feedbag.chttp://developer.pidgin.im/viewmtn/revision/info/757272a78a8ca6027d518e614712c3399e34dda3http://pidgin.im/news/security/?id=57http://secunia.com/advisories/47219http://secunia.com/advisories/47234http://www.mandriva.com/security/advisories?name=MDVSA-2011:183http://www.openwall.com/lists/oss-security/2011/12/10/1http://www.openwall.com/lists/oss-security/2011/12/10/2http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1821.htmlhttp://www.securityfocus.com/bid/51010https://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18408http://developer.pidgin.im/viewmtn/revision/diff/bc79b1bf09dcfa1d8edac86a06761fce7416e69c/with/757272a78a8ca6027d518e614712c3399e34dda3/libpurple/protocols/oscar/family_feedbag.chttp://developer.pidgin.im/viewmtn/revision/info/757272a78a8ca6027d518e614712c3399e34dda3http://pidgin.im/news/security/?id=57http://secunia.com/advisories/47219http://secunia.com/advisories/47234http://www.mandriva.com/security/advisories?name=MDVSA-2011:183http://www.openwall.com/lists/oss-security/2011/12/10/1http://www.openwall.com/lists/oss-security/2011/12/10/2http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1821.htmlhttp://www.securityfocus.com/bid/51010https://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18408
2011-12-25
Published