CVE-2014-3695
published 2014-10-29CVE-2014-3695: markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.87%
85.3th percentile
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pidgin | < pidgin 2.10.10-1 (bookworm) | pidgin 2.10.10-1 (bookworm) |
| pidgin | pidgin | <= 2.10.9 | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | — | — |
| pidgin | pidgin | >= 0 < 2.10.10-1 | 2.10.10-1 |
| pidgin | pidgin | >= 0 < 2.10.10-1 | 2.10.10-1 |
| pidgin | pidgin | >= 0 < 2.10.10-1 | 2.10.10-1 |
| pidgin | pidgin | >= 0 < 2.10.10-1 | 2.10.10-1 |
| pidgin | pidgin | >= 0 < 1:2.10.9-0ubuntu3.2 | 1:2.10.9-0ubuntu3.2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.4MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5p8v-243c-373h: markup
ghsa_unreviewed·2022-05-14
CVE-2014-3695 [MEDIUM] CWE-119 GHSA-5p8v-243c-373h: markup
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.
OSV
CVE-2014-3695: markup
osv·2014-10-29·CVSS 5.0
CVE-2014-3695 [MEDIUM] CVE-2014-3695: markup
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.
OSV
pidgin vulnerabilities
osv·2014-10-28·CVSS 6.4
CVE-2014-3694 [MEDIUM] pidgin vulnerabilities
pidgin vulnerabilities
Jacob Appelbaum and an anonymous person discovered that Pidgin incorrectly
handled certificate validation. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3694)
Yves Younan and Richard Johnson discovered that Pidgin incorrectly handled
certain malformed MXit emoticons. A malicious remote server or a
machine-in-the-middle could use this issue to cause Pidgin to crash,
resulting in a denial of service. (CVE-2014-3695)
Yves Younan and Richard Johnson discovered that Pidgin incorrectly handled
certain malformed Groupwise messages. A malicious remote server or a
machine-in-the-middle could use this issue to cause Pidgin to crash,
resulting in a denial of service. (
Ubuntu
Pidgin vulnerabilities
vendor_ubuntu·2014-10-28·CVSS 6.4
CVE-2014-3694 [MEDIUM] Pidgin vulnerabilities
Title: Pidgin vulnerabilities
Summary: Several security issues were fixed in Pidgin.
Jacob Appelbaum and an anonymous person discovered that Pidgin incorrectly
handled certificate validation. A remote attacker could exploit this to
perform a machine-in-the-middle attack to view sensitive information or alter
encrypted communications. (CVE-2014-3694)
Yves Younan and Richard Johnson discovered that Pidgin incorrectly handled
certain malformed MXit emoticons. A malicious remote server or a
machine-in-the-middle could use this issue to cause Pidgin to crash,
resulting in a denial of service. (CVE-2014-3695)
Yves Younan and Richard Johnson discovered that Pidgin incorrectly handled
certain malformed Groupwise messages. A malicious remote server or a
machine-in-the-middle could use this issu
Red Hat
pidgin: crash in Mxit protocol plug-in
vendor_redhat·2014-10-22·CVSS 5.0
CVE-2014-3695 [MEDIUM] pidgin: crash in Mxit protocol plug-in
pidgin: crash in Mxit protocol plug-in
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.
A denial of service flaw was found in the way Pidgin's Mxit plug-in handled emoticons. A malicious remote server or a man-in-the-middle attacker could potentially use this flaw to crash Pidgin by sending a specially crafted emoticon.
Package: pidgin (Red Hat Enterprise Linux 5) - Will not fix
Package: pidgin (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2014-3695: pidgin - markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allow...
vendor_debian·2014·CVSS 5.0
CVE-2014-3695 [MEDIUM] CVE-2014-3695: pidgin - markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allow...
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.
Scope: local
bookworm: resolved (fixed in 2.10.10-1)
bullseye: resolved (fixed in 2.10.10-1)
forky: resolved (fixed in 2.10.10-1)
sid: resolved (fixed in 2.10.10-1)
trixie: resolved (fixed in 2.10.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3694 CVE-2014-3695 CVE-2014-3696 CVE-2014-3698 pidgin: various flaws [fedora-all]
bugzilla·2014-10-23·CVSS 6.4
CVE-2014-3694 [MEDIUM] CVE-2014-3694 CVE-2014-3695 CVE-2014-3696 CVE-2014-3698 pidgin: various flaws [fedora-all]
CVE-2014-3694 CVE-2014-3695 CVE-2014-3696 CVE-2014-3698 pidgin: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-3695 pidgin: crash in Mxit protocol plug-in
bugzilla·2014-10-21·CVSS 5.0
CVE-2014-3695 [MEDIUM] CVE-2014-3695 pidgin: crash in Mxit protocol plug-in
CVE-2014-3695 pidgin: crash in Mxit protocol plug-in
A flaw was found in the MXit protocol plug-in. A malicious server or man-in-the-middle attacker could trigger this issue and cause Pidgin to crash by sending a specially-crafted emoticon.
Acknowledgements:
Name: the Pidgin project
Upstream: Yves Younan (Cisco Talos), Richard Johnson (Cisco Talos)
Discussion:
Created attachment 948787
patch from upstream
---
Public now:
http://www.pidgin.im/news/security/?id=87
---
Created pidgin tracking bugs for this issue:
Affects: fedora-all [bug 1155838]
---
pidgin-2.10.10-2.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
pidgin-2.10.10-1.fc20 has been pushed to the Fedora 20 stable repository. If proble
Talos
Talos Discovered Three More Vulnerabilities in Pidgin
blogs_talos·2014-11-07·CVSS 5.0
CVE-2014-3697 [MEDIUM] Talos Discovered Three More Vulnerabilities in Pidgin
This post was authored by Yves Younan and edited by Armin Pelkmann.
> Table of contents
>
>
>
> CVE-2014-3697, VRT-2014-0205
>
> CVE-2014-3696, VRT-2014-0204
> CVE-2014-3695, VRT-2014-0203
Cisco Talos is announcing the discovery and patching of another three 3 CVE vulnerabilities in Pidgin (An open-source multi-platform instant messaging client - see wikipedia page). These vulnerabilities were discovered by our team and reported to the Pidgin team. They were found during our initial look at Pidgin which resulted in the first 4 vulnerabilities released in January, but were reported to Pidgin a little later and took longer to get patched. Now that these vulnerabilities were patched in the latest version of Pidgin, 2.10.10, we want to publicly disclose our findings.
The first vulnerability
Talos
Talos Discovered Three More Vulnerabilities in Pidgin
blogs_talos·2014-11-07·CVSS 5.0
CVE-2014-3697 [MEDIUM] Talos Discovered Three More Vulnerabilities in Pidgin
## Talos Discovered Three More Vulnerabilities in Pidgin
This post was authored by Yves Younan and edited by Armin Pelkmann.
Table of contents
CVE-2014-3697, VRT-2014-0205 CVE-2014-3696, VRT-2014-0204 CVE-2014-3695, VRT-2014-0203
Cisco Talos is announcing the discovery and patching of another three 3 CVE vulnerabilities in Pidgin (An open-source multi-platform instant messaging client - see wikipedia page ). These vulnerabilities were discovered by our team and reported to the Pidgin team. They were found during our initial look at Pidgin which resulted in the first 4 vulnerabilities released in January , but were reported to Pidgin a little later and took longer to get patched. Now that these vulnerabilities were patched in the latest version of Pidgin, 2.10.10 , we want to publicly d
http://hg.pidgin.im/pidgin/main/rev/6436e14bdb9dhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00023.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00037.htmlhttp://pidgin.im/news/security/?id=87http://secunia.com/advisories/60741http://secunia.com/advisories/61968http://www.debian.org/security/2014/dsa-3055http://www.ubuntu.com/usn/USN-2390-1https://access.redhat.com/errata/RHSA-2017:1854http://hg.pidgin.im/pidgin/main/rev/6436e14bdb9dhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00023.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00037.htmlhttp://pidgin.im/news/security/?id=87http://secunia.com/advisories/60741http://secunia.com/advisories/61968http://www.debian.org/security/2014/dsa-3055http://www.ubuntu.com/usn/USN-2390-1https://access.redhat.com/errata/RHSA-2017:1854
2014-10-29
Published