CVE-2011-4603
published 2011-12-17CVE-2011-4603: The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.73%
88.6th percentile
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.1-1 (bookworm) | pidgin 2.10.1-1 (bookworm) |
| pidgin | pidgin | <= 2.10.0 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: SILC remote crash on channel messages
vendor_redhat·2011-12-11·CVSS 4.3
CVE-2011-4603 [MEDIUM] pidgin: SILC remote crash on channel messages
pidgin: SILC remote crash on channel messages
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Statement: Not vulnerable. This issue did not affect the version of pidgin as shipped with Red Hat Enterprise Linux 6 as it explicitly disables support for the SILC protocol.
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-4603: pidgin - The silc_channel_message function in ops.c in the SILC protocol plugin in libpur...
vendor_debian·2011·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603: pidgin - The silc_channel_message function in ops.c in the SILC protocol plugin in libpur...
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Scope: local
bookworm: resolved (fixed in 2.10.1-1)
bullseye: resolved (fixed in 2.10.1-1)
forky: resolved (fixed in 2.10.1-1)
sid: resolved (fixed in 2.10.1-1)
trixie: resolved (fixed in 2.10.1-1)
GHSA
GHSA-6f79-g335-f9mf: The silc_channel_message function in ops
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-4603 [MEDIUM] CWE-20 GHSA-6f79-g335-f9mf: The silc_channel_message function in ops
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
OSV
CVE-2011-4603: The silc_channel_message function in ops
osv·2011-12-17·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603: The silc_channel_message function in ops
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4603 pidgin: SILC remote crash on channel messages
bugzilla·2011-12-12·CVSS 4.3
CVE-2011-4603 [MEDIUM] CVE-2011-4603 pidgin: SILC remote crash on channel messages
CVE-2011-4603 pidgin: SILC remote crash on channel messages
When receiving various incoming messages, the SILC protocol plugin failed to validate that a piece of text was UTF-8. In some cases invalid UTF-8 data would lead to a crash. This vulnerability is similar to CVE-2011-3594, but occurs in a different piece of code and was fixed at a later date.
Reference:
http://pidgin.im/news/security/?id=59
Patch: http://developer.pidgin.im/viewmtn/revision/info/afb9ede3de989f217f03d5670cca00e628bd11f1
Discussion:
Created pidgin tracking bugs for this issue
Affects: fedora-all [bug 766454]
---
Acknowledgements:
Red Hat would like to thank the Pidgin project for reporting this issue. Upstream acknowledges Diego Bauche Madero from IOActive as the original reporter.
---
This issue has been a
Bugzilla
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
bugzilla·2011-12-12·CVSS 5.0
CVE-2011-4601 [MEDIUM] CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
CVE-2011-4601 CVE-2011-4602 CVE-2011-4603 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
http://developer.pidgin.im/viewmtn/revision/diff/c7b95cc3be0590b52edc02d4750ae62844c1acb6/with/afb9ede3de989f217f03d5670cca00e628bd11f1/libpurple/protocols/silc/ops.chttp://developer.pidgin.im/viewmtn/revision/info/afb9ede3de989f217f03d5670cca00e628bd11f1http://secunia.com/advisories/47234http://www.pidgin.im/news/security/?id=59http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.securityfocus.com/bid/51074https://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18303http://developer.pidgin.im/viewmtn/revision/diff/c7b95cc3be0590b52edc02d4750ae62844c1acb6/with/afb9ede3de989f217f03d5670cca00e628bd11f1/libpurple/protocols/silc/ops.chttp://developer.pidgin.im/viewmtn/revision/info/afb9ede3de989f217f03d5670cca00e628bd11f1http://secunia.com/advisories/47234http://www.pidgin.im/news/security/?id=59http://www.redhat.com/support/errata/RHSA-2011-1820.htmlhttp://www.securityfocus.com/bid/51074https://hermes.opensuse.org/messages/13195955https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18303
2011-12-17
Published