| Summary: | pidgin new security issues: CVE-2012-1178 and CVE-2011-4939 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, mageia, mageia, sysadmin-bugs, tmb |
| Version: | 1 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://pidgin.im/news/security/?id=61 | ||
| Whiteboard: | |||
| Source RPM: | pidgin-2.10.1-1.mga1.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 5624 | ||
|
Description
David Walser
2012-03-15 23:07:14 CET
David Walser
2012-03-15 23:07:30 CET
CC:
(none) =>
mageia
Manuel Hiebel
2012-03-16 00:04:27 CET
Assignee:
bugsquad =>
mageia Advisory: This update of pidgin fix CVE-2012-1178 to prevent possible MSN remote crash because of bad encoded text received. Packages: - pidgin-2.10.1-1.1.mga1 - pidgin-plugins-2.10.1-1.1.mga1 - pidgin-perl-2.10.1-1.1.mga1 - pidgin-tcl-2.10.1-1.1.mga1 - pidgin-silc-2.10.1-1.1.mga1 - lib64purple-devel-2.10.1-1.1.mga1 - lib64purple0-2.10.1-1.1.mga1 - lib64finch0-2.10.1-1.1.mga1 - finch-2.10.1-1.1.mga1 - pidgin-bonjour-2.10.1-1.1.mga1 - pidgin-meanwhile-2.10.1-1.1.mga1 - pidgin-client-2.10.1-1.1.mga1 - pidgin-i18n-2.10.1-1.1.mga1 - pidgin-debug-2.10.1-1.1.mga1 Status:
NEW =>
ASSIGNED
Damien Lallement
2012-03-16 02:23:44 CET
Hardware:
i586 =>
All Testing complete on i586 for the srpm pidgin-2.10.1-1.1.mga1.src.rpm Just testing that pidgin is working with my Yahoo, hotmail, and gmail accounts. Same with finch. CC:
(none) =>
davidwhodgins Just for reference, Mandriva says there's another CVE also fixed in this version: CVE-2011-4939 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4939 http://pidgin.im/news/security/?id=60 http://www.mandriva.com/en/support/security/advisories/?dis=2011&name=MDVSA-2012:029 (In reply to comment #3) > Just for reference, Mandriva says there's another CVE also fixed in this > version It's not just Mandriva who says this. :) Simply look at this list, and check the Fixed In column: http://pidgin.im/news/security/ It was for CVE-2012-1178, not CVE-2011-4939. My bad... As Mandriva having pidgin 2.10.2 in testing, I will change the update request for 2.10.2 (instead of 2.10.1 + patch). I will reassign to QA when available. Assignee:
qa-bugs =>
mageia pidgin-2.10.2-1.1.mga1.src.rpm now available in core/updates_testing. Assignee:
mageia =>
qa-bugs Advisory: This update of pidgin fix CVE-2012-1178 and CVE-2011-4939. It also upgrade to 2.10.2 to allow upgrade from Mandriva 2010.2. Summary:
pidgin new security issue CVE-2012-1178 =>
pidgin new security issues: CVE-2012-1178 and CVE-2011-4939 Tested on x86_64, seems to work as before. CC:
(none) =>
sander.lepik Tested OK i586. No PoC's. Validating Advisory ------------ This update to pidgin fixes two vulnerabilities. It also upgrades to 2.10.2 to allow upgrade from Mandriva 2010.2. CVE-2012-1178 - The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding. CVE-2011-4939 - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1178 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4939 ------------- SRPM: pidgin-2.10.2-1.1.mga1.src.rpm Could sysadmin please push from core/updates_testing to core/updates Thanks! Keywords:
(none) =>
validated_update Update pushed. Status:
ASSIGNED =>
RESOLVED Note that 2.10.2 broke the status of MSN buddies, see http://developer.pidgin.im/wiki/ChangeLog "2.10.3 fixes a problem with MSN buddies appearing online when they shouldn't." This is a regression in 2.10.2, so people upgrading to this version will be affected by this bug. (In reply to comment #11) > Note that 2.10.2 broke the status of MSN buddies, see > http://developer.pidgin.im/wiki/ChangeLog > > "2.10.3 fixes a problem with MSN buddies appearing online when they shouldn't." > > This is a regression in 2.10.2, so people upgrading to this version will be > affected by this bug. Could you open a new bug report for this?
Frédéric "LpSolit" Buclin
2012-04-27 01:06:00 CEST
Blocks:
(none) =>
5624 |