CVE-2011-4939
published 2012-03-15CVE-2011-4939: The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference…
PriorityP424medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
3.55%
88.0th percentile
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.2-1 (bookworm) | pidgin 2.10.2-1 (bookworm) |
| pidgin | pidgin | <= 2.10.1 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: NULL pointer dereference in the XMPP protocol plug-in by renaming user name
vendor_redhat·2011-07-08·CVSS 6.4
CVE-2011-4939 [MEDIUM] CWE-476 pidgin: NULL pointer dereference in the XMPP protocol plug-in by renaming user name
pidgin: NULL pointer dereference in the XMPP protocol plug-in by renaming user name
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
Statement: Not Vulnerable. This issue does not affect the version of pidgin as shipped with Red Hat Enterprise Linux 5 and 6.
Package: pidgin (Red Hat Enterprise Linux 5) - Not affected
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-4939: pidgin - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 a...
vendor_debian·2011·CVSS 6.4
CVE-2011-4939 [MEDIUM] CVE-2011-4939: pidgin - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 a...
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
Scope: local
bookworm: resolved (fixed in 2.10.2-1)
bullseye: resolved (fixed in 2.10.2-1)
forky: resolved (fixed in 2.10.2-1)
sid: resolved (fixed in 2.10.2-1)
trixie: resolved (fixed in 2.10.2-1)
GHSA
GHSA-fqpj-4v5c-wf35: The pidgin_conv_chat_rename_user function in gtkconv
ghsa_unreviewed·2022-05-14
CVE-2011-4939 [MEDIUM] GHSA-fqpj-4v5c-wf35: The pidgin_conv_chat_rename_user function in gtkconv
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
OSV
CVE-2011-4939: The pidgin_conv_chat_rename_user function in gtkconv
osv·2012-03-15·CVSS 6.4
CVE-2011-4939 [MEDIUM] CVE-2011-4939: The pidgin_conv_chat_rename_user function in gtkconv
The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.
No detection rules found.
No public exploits indexed.
http://developer.pidgin.im/ticket/14392http://developer.pidgin.im/viewmtn/revision/diff/10ead4688e3af4132d454fa3bc241480500651c9/with/d1d77da56217f3a083e1d459bef054db9f1d5699/pidgin/gtkconv.chttp://developer.pidgin.im/viewmtn/revision/info/d1d77da56217f3a083e1d459bef054db9f1d5699http://pidgin.im/news/security/?id=60http://www.mandriva.com/security/advisories?name=MDVSA-2012:029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18406http://developer.pidgin.im/ticket/14392http://developer.pidgin.im/viewmtn/revision/diff/10ead4688e3af4132d454fa3bc241480500651c9/with/d1d77da56217f3a083e1d459bef054db9f1d5699/pidgin/gtkconv.chttp://developer.pidgin.im/viewmtn/revision/info/d1d77da56217f3a083e1d459bef054db9f1d5699http://pidgin.im/news/security/?id=60http://www.mandriva.com/security/advisories?name=MDVSA-2012:029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18406
2012-03-15
Published