CVE-2011-4602
published 2011-12-17CVE-2011-4602: The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.72%
88.6th percentile
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.1-1 (bookworm) | pidgin 2.10.1-1 (bookworm) |
| pidgin | pidgin | <= 2.10.0 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6vj-77mr-4rfr: The XMPP protocol plugin in libpurple in Pidgin before 2
ghsa_unreviewed·2022-05-17
CVE-2011-4602 [MEDIUM] CWE-20 GHSA-f6vj-77mr-4rfr: The XMPP protocol plugin in libpurple in Pidgin before 2
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
OSV
CVE-2011-4602: The XMPP protocol plugin in libpurple in Pidgin before 2
osv·2011-12-17·CVSS 5.0
CVE-2011-4602 [MEDIUM] CVE-2011-4602: The XMPP protocol plugin in libpurple in Pidgin before 2
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
vendor_redhat·2011-12-10·CVSS 5.0
CVE-2011-4602 [MEDIUM] pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
Debian
CVE-2011-4602: pidgin - The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly ...
vendor_debian·2011·CVSS 5.0
CVE-2011-4602 [MEDIUM] CVE-2011-4602: pidgin - The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly ...
The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.
Scope: local
bookworm: resolved (fixed in 2.10.1-1)
bullseye: resolved (fixed in 2.10.1-1)
forky: resolved (fixed in 2.10.1-1)
sid: resolved (fixed in 2.10.1-1)
trixie: resolved (fixed in 2.10.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
bugzilla·2011-12-12·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2011-4602 pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
bugzilla·2011-12-08·CVSS 5.0
CVE-2011-4602 [MEDIUM] CVE-2011-4602 pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
CVE-2011-4602 pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
Multiple NULL pointer dereference flaws were found in the way the Jingle extension of the XMPP protocol plug-in of Pidgin, a Gtk+ based multiprotocol instant messaging client, processed certain Jingle stanzas. A remote, authenticated user could use these flaws to cause denial of service (Pidgin crash) via specially-crafted Jingle multimedia message.
Reference:
http://pidgin.im/news/security/?id=58
Patch: http://developer.pidgin.im/viewmtn/revision/info/fb216fc88b085afc06d9a15209519cde1f4df6c6
Discussion:
This issues affect the versions of the pidgin package, as shipped with Red Hat Enterprise Linux 4, 5, and 6.
--
This issue affect the versions of the pidgin p
http://developer.pidgin.im/viewmtn/revision/info/fb216fc88b085afc06d9a15209519cde1f4df6c6http://pidgin.im/news/security/?id=58http://secunia.com/advisories/47219http://secunia.com/advisories/47234http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1821.htmlhttps://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18420http://developer.pidgin.im/viewmtn/revision/info/fb216fc88b085afc06d9a15209519cde1f4df6c6http://pidgin.im/news/security/?id=58http://secunia.com/advisories/47219http://secunia.com/advisories/47234http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1821.htmlhttps://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18420
2011-12-17
Published