CVE-2013-0274
published 2013-02-16CVE-2013-0274: upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of…
PriorityP410low2.9CVSS 2.0
AVAACMAuNCNINAP
EPSS
1.35%
68.6th percentile
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.6-3 (bookworm) | pidgin 2.10.6-3 (bookworm) |
| linux | linux_kernel | >= 0 < 3.13.0-48.80 | 3.13.0-48.80 |
| pidgin | pidgin | <= 2.10.6 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
CVSS provenance
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
osv2.9LOW
vendor_ubuntu5.0MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2013-02-25·CVSS 5.0
CVE-2013-0271 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Chris Wysopal discovered that Pidgin incorrectly handled file transfers in
the MXit protocol handler. A remote attacker could use this issue to create
or overwrite arbitrary files. This issue only affected Ubuntu 11.10,
Ubuntu 12.04 LTS and Ubuntu 12.10. (CVE-2013-0271)
It was discovered that Pidgin incorrectly handled long HTTP headers in the
MXit protocol handler. A malicious remote server could use this issue to
execute arbitrary code. (CVE-2013-0272)
It was discovered that Pidgin incorrectly handled long user IDs in the
Sametime protocol handler. A malicious remote server could use this issue
to cause Pidgin to crash, resulting in a denial of service. (CVE-2013-0273)
It was discovered that Pidgin
Red Hat
pidgin: missing nul termination of long values in UPnP responses
vendor_redhat·2013-02-13·CVSS 2.9
CVE-2013-0274 [LOW] pidgin: missing nul termination of long values in UPnP responses
pidgin: missing nul termination of long values in UPnP responses
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
Package: pidgin (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2013-0274: pidgin - upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long str...
vendor_debian·2013·CVSS 2.9
CVE-2013-0274 [LOW] CVE-2013-0274: pidgin - upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long str...
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
Scope: local
bookworm: resolved (fixed in 2.10.6-3)
bullseye: resolved (fixed in 2.10.6-3)
forky: resolved (fixed in 2.10.6-3)
sid: resolved (fixed in 2.10.6-3)
trixie: resolved (fixed in 2.10.6-3)
GHSA
GHSA-63v2-6jjq-v396: upnp
ghsa_unreviewed·2022-05-05
CVE-2013-0274 [LOW] GHSA-63v2-6jjq-v396: upnp
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
OSV
linux vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2015-0274 linux vulnerabilities
linux vulnerabilities
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in the crypto subsystem when screening module names
for au
OSV
CVE-2013-0274: upnp
osv·2013-02-16·CVSS 2.9
CVE-2013-0274 [LOW] CVE-2013-0274: upnp
upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0271 CVE-2013-0272 CVE-2013-0273 CVE-2013-0274 pidgin various flaws [fedora-all]
bugzilla·2013-02-13·CVSS 5.0
CVE-2013-0271 [MEDIUM] CVE-2013-0271 CVE-2013-0272 CVE-2013-0273 CVE-2013-0274 pidgin various flaws [fedora-all]
CVE-2013-0271 CVE-2013-0272 CVE-2013-0273 CVE-2013-0274 pidgin various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: th
Bugzilla
CVE-2013-0274 pidgin: missing nul termination of long values in UPnP responses
bugzilla·2013-02-11·CVSS 2.9
CVE-2013-0274 [LOW] CVE-2013-0274 pidgin: missing nul termination of long values in UPnP responses
CVE-2013-0274 pidgin: missing nul termination of long values in UPnP responses
A security flaw was found in the way UPnP implementation of libPurple processed certain UPnP responses (UPnP responses with overly long 'service type', 'public IP address', 'internal IP address', and 'AddRemovePortMapping protocol' values). A remote attacker could send a specially-crafted UPnP response that, when processed by Pidgin, would lead to pidgin executable crash.
Upstream ticket:
[1] http://pidgin.im/news/security/?id=68
Discussion:
Created attachment 696218
Local copy of (by Pidgin upstream) proposed patch to fix the CVE-2013-0274 issue
---
This issue affects the versions of the pidgin package, as shipped with Red Hat Enterprise Linux 5 and 6.
--
This issue affects the versions of the pidgin pa
http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.htmlhttp://www.pidgin.im/news/security/?id=68http://www.ubuntu.com/usn/USN-1746-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18221http://hg.pidgin.im/pidgin/main/rev/ad7e7fb98db3http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00007.htmlhttp://www.pidgin.im/news/security/?id=68http://www.ubuntu.com/usn/USN-1746-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18221
2013-02-16
Published