CVE-2012-3374
published 2012-07-07CVE-2012-3374: Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.40%
92.9th percentile
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.6-1 (bookworm) | pidgin 2.10.6-1 (bookworm) |
| pidgin | pidgin | <= 2.10.4 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q7fv-r5c8-cpcg: Buffer overflow in markup
ghsa_unreviewed·2022-05-17
CVE-2012-3374 [HIGH] CWE-119 GHSA-q7fv-r5c8-cpcg: Buffer overflow in markup
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
OSV
CVE-2012-3374: Buffer overflow in markup
osv·2012-07-07·CVSS 7.5
CVE-2012-3374 [HIGH] CVE-2012-3374: Buffer overflow in markup
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2012-07-09·CVSS 5.0
CVE-2011-4601 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the
Red Hat
pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
vendor_redhat·2012-07-05·CVSS 7.5
CVE-2012-3374 [HIGH] pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
Debian
CVE-2012-3374: pidgin - Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin b...
vendor_debian·2012·CVSS 7.5
CVE-2012-3374 [HIGH] CVE-2012-3374: pidgin - Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin b...
Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.
Scope: local
bookworm: resolved (fixed in 2.10.6-1)
bullseye: resolved (fixed in 2.10.6-1)
forky: resolved (fixed in 2.10.6-1)
sid: resolved (fixed in 2.10.6-1)
trixie: resolved (fixed in 2.10.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in [fedora-all]
bugzilla·2012-07-05·CVSS 7.5
CVE-2012-3374 [HIGH] CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in [fedora-all]
CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/upda
Bugzilla
CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
bugzilla·2012-07-03·CVSS 7.5
CVE-2012-3374 [HIGH] CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
CVE-2012-3374 pidgin: Stack-based buffer overwrite in MXit protocol libPurple plug-in
A stack-based buffer overwrite flaw was found in the way MXit protocol plug-in implementation of libPurple, the core of an instant messaging program, such as Pidgin, replaced certain custom emoticon tags with corresponding image tags by processing received RX message data, prior returning the instant message to the user interface for it's presentation to the user. A remote attacker could provide a RX message with specially-crafted emoticon tags, that when processed by the libPurple's MXit protocol plug-in by an application linked against libPurple could lead to that application crash or, potentially, arbitrary code execution with the privileges of the user running the application.
Upstream ticket (priva
http://hg.pidgin.im/pidgin/main/rev/ded93865ef42http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1102.htmlhttp://secunia.com/advisories/50005http://www.mandriva.com/security/advisories?name=MDVSA-2012:105http://www.pidgin.im/news/security/index.php?id=64https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17678http://hg.pidgin.im/pidgin/main/rev/ded93865ef42http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1102.htmlhttp://secunia.com/advisories/50005http://www.mandriva.com/security/advisories?name=MDVSA-2012:105http://www.pidgin.im/news/security/index.php?id=64https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17678
2012-07-07
Published