CVE-2012-2214
published 2012-07-03CVE-2012-2214: proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated…
PriorityP411low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
2.20%
80.5th percentile
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.4-1 (bookworm) | pidgin 2.10.4-1 (bookworm) |
| pidgin | pidgin | <= 2.10.3 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_ubuntu5.0MEDIUM
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
vendor_redhat·2012-05-06·CVSS 3.5
CVE-2012-2214 [LOW] pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
Statement: Not Vulnerable. This issue does not affect the version of pidgin as shipped with Red Hat Enterprise Linux 5 and 6.
Package: pidgin (Red Hat Enterprise Linux 5) - Not affected
Package: pidgin (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-2214: pidgin - proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled S...
vendor_debian·2012·CVSS 3.5
CVE-2012-2214 [LOW] CVE-2012-2214: pidgin - proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled S...
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
Scope: local
bookworm: resolved (fixed in 2.10.4-1)
bullseye: resolved (fixed in 2.10.4-1)
forky: resolved (fixed in 2.10.4-1)
sid: resolved (fixed in 2.10.4-1)
trixie: resolved (fixed in 2.10.4-1)
GHSA
GHSA-8xpc-q358-5r82: proxy
ghsa_unreviewed·2022-05-14
CVE-2012-2214 [LOW] GHSA-8xpc-q358-5r82: proxy
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
OSV
CVE-2012-2214: proxy
osv·2012-07-03·CVSS 3.5
CVE-2012-2214 [LOW] CVE-2012-2214: proxy
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2214 pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
bugzilla·2012-05-07·CVSS 3.5
CVE-2012-2214 [LOW] CVE-2012-2214 pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
CVE-2012-2214 pidgin: Invalid memory dereference in the XMPP protocol plug-in by processing serie of specially-crafted file transfer requests
A denial service flaw was found in the way XMPP protocol plug-in of Pidgin, a Gtk+ based multiprotocol instant messaging client, performed cleanup for certain SOCKS5 connections. A remote attacker, being present on the buddy list of the victim, and able to trick the victim into accepting of a serie of specially-crafted XMPP file transfer requests, could use this flaw to cause pidgin executable crash.
Upstream advisory:
[1] http://www.pidgin.im/news/security/?id=62
Relevant upstream patch:
[2] http://developer.pidgin.im/viewmtn/revision/info/d991ff6d558d185527a09eae0378edb3fc7057a5
Discussion:
This issue affects the versions of the pidgin package
Bugzilla
CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
bugzilla·2012-05-07·CVSS 3.5
CVE-2012-2214 [LOW] CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=819446
http://hg.pidgin.im/pidgin/main/rev/5f9d676cefdbhttp://pidgin.im/news/security/?id=62http://www.mandriva.com/security/advisories?name=MDVSA-2012:082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17886http://hg.pidgin.im/pidgin/main/rev/5f9d676cefdbhttp://pidgin.im/news/security/?id=62http://www.mandriva.com/security/advisories?name=MDVSA-2012:082https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17886
2012-07-03
Published