CVE-2012-2318
published 2012-07-03CVE-2012-2318: msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.71%
74.9th percentile
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.4-1 (bookworm) | pidgin 2.10.4-1 (bookworm) |
| pidgin | pidgin | <= 2.10.3 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
vendor_redhat·2012-05-06·CVSS 5.0
CVE-2012-2318 [MEDIUM] pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
Debian
CVE-2012-2318: pidgin - msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not p...
vendor_debian·2012·CVSS 5.0
CVE-2012-2318 [MEDIUM] CVE-2012-2318: pidgin - msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not p...
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
Scope: local
bookworm: resolved (fixed in 2.10.4-1)
bullseye: resolved (fixed in 2.10.4-1)
forky: resolved (fixed in 2.10.4-1)
sid: resolved (fixed in 2.10.4-1)
trixie: resolved (fixed in 2.10.4-1)
GHSA
GHSA-5cxv-7whw-jpv5: msg
ghsa_unreviewed·2022-05-14
CVE-2012-2318 [MEDIUM] CWE-20 GHSA-5cxv-7whw-jpv5: msg
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
OSV
CVE-2012-2318: msg
osv·2012-07-03·CVSS 5.0
CVE-2012-2318 [MEDIUM] CVE-2012-2318: msg
msg.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.4 does not properly handle crafted characters, which allows remote servers to cause a denial of service (application crash) by placing these characters in a text/plain message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2318 pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
bugzilla·2012-05-07·CVSS 5.0
CVE-2012-2318 [MEDIUM] CVE-2012-2318 pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
CVE-2012-2318 pidgin: Improper validation of incoming plaintext messages in MSN protocol plug-in
An improper input validation flaw was found in the way MSN protocol plug-in of Pidgin, a Gtk+ based multiprotocol instant messaging client, performed parsing of MSN message payload containing certain characters. If a remote server provided a specially-crafted MSN notification message or remote attacker, being present on the buddy list of the victim, provided a specially-crafted MSN offline instant message, it could lead to pidgin executable crash.
Upstream advisory:
[1] http://www.pidgin.im/news/security/?id=63
Relevant upstream patch:
[2] http://developer.pidgin.im/viewmtn/revision/info/94cbd5a68ee237c970d8bd6d9d53106f1b9627ad
CVE Request:
[3] http://www.openwall.com/lists/oss-security/201
Bugzilla
CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
bugzilla·2012-05-07·CVSS 3.5
CVE-2012-2214 [LOW] CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
CVE-2012-2214 CVE-2012-2318 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=819446
http://hg.pidgin.im/pidgin/main/rev/4d6bcb4f4ea4http://pidgin.im/news/security/?id=63http://rhn.redhat.com/errata/RHSA-2012-1102.htmlhttp://secunia.com/advisories/50005http://www.mandriva.com/security/advisories?name=MDVSA-2012:082http://www.securityfocus.com/bid/53400https://hermes.opensuse.org/messages/15136503https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17448http://hg.pidgin.im/pidgin/main/rev/4d6bcb4f4ea4http://pidgin.im/news/security/?id=63http://rhn.redhat.com/errata/RHSA-2012-1102.htmlhttp://secunia.com/advisories/50005http://www.mandriva.com/security/advisories?name=MDVSA-2012:082http://www.securityfocus.com/bid/53400https://hermes.opensuse.org/messages/15136503https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17448
2012-07-03
Published