Bug 4965 - pidgin new security issues: CVE-2012-1178 and CVE-2011-4939
Summary: pidgin new security issues: CVE-2012-1178 and CVE-2011-4939
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://pidgin.im/news/security/?id=61
Whiteboard:
Keywords: validated_update
Depends on:
Blocks: 5624
  Show dependency treegraph
 
Reported: 2012-03-15 23:07 CET by David Walser
Modified: 2012-04-27 01:06 CEST (History)
5 users (show)

See Also:
Source RPM: pidgin-2.10.1-1.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-03-15 23:07:14 CET
This issue is a denial of service / crashing issue in the MSN plugin.

Info is here:
http://pidgin.im/news/security/?id=61
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1178
David Walser 2012-03-15 23:07:30 CET

CC: (none) => mageia

Manuel Hiebel 2012-03-16 00:04:27 CET

Assignee: bugsquad => mageia

Comment 1 Damien Lallement 2012-03-16 02:20:57 CET
Advisory:
This update of pidgin fix CVE-2012-1178 to prevent possible MSN remote crash because of bad encoded text received.

Packages:
- pidgin-2.10.1-1.1.mga1
- pidgin-plugins-2.10.1-1.1.mga1
- pidgin-perl-2.10.1-1.1.mga1
- pidgin-tcl-2.10.1-1.1.mga1
- pidgin-silc-2.10.1-1.1.mga1
- lib64purple-devel-2.10.1-1.1.mga1
- lib64purple0-2.10.1-1.1.mga1
- lib64finch0-2.10.1-1.1.mga1
- finch-2.10.1-1.1.mga1
- pidgin-bonjour-2.10.1-1.1.mga1
- pidgin-meanwhile-2.10.1-1.1.mga1
- pidgin-client-2.10.1-1.1.mga1
- pidgin-i18n-2.10.1-1.1.mga1
- pidgin-debug-2.10.1-1.1.mga1

Status: NEW => ASSIGNED
Assignee: mageia => qa-bugs

Damien Lallement 2012-03-16 02:23:44 CET

Hardware: i586 => All

Comment 2 Dave Hodgins 2012-03-16 03:41:57 CET
Testing complete on i586 for the srpm
pidgin-2.10.1-1.1.mga1.src.rpm

Just testing that pidgin is working with my Yahoo, hotmail, and gmail
accounts.  Same with finch.

CC: (none) => davidwhodgins

Comment 3 David Walser 2012-03-16 12:33:25 CET
Just for reference, Mandriva says there's another CVE also fixed in this version:
CVE-2011-4939

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4939
http://pidgin.im/news/security/?id=60
http://www.mandriva.com/en/support/security/advisories/?dis=2011&name=MDVSA-2012:029
Comment 4 Frédéric "LpSolit" Buclin 2012-03-17 17:11:35 CET
(In reply to comment #3)
> Just for reference, Mandriva says there's another CVE also fixed in this
> version

It's not just Mandriva who says this. :) Simply look at this list, and check the Fixed In column: http://pidgin.im/news/security/
Comment 5 Damien Lallement 2012-03-19 12:06:53 CET
It was for CVE-2012-1178, not CVE-2011-4939.
My bad...
As Mandriva having pidgin 2.10.2 in testing, I will change the update request for 2.10.2 (instead of 2.10.1 + patch).
I will reassign to QA when available.

Assignee: qa-bugs => mageia

Comment 6 Damien Lallement 2012-03-19 12:25:36 CET
pidgin-2.10.2-1.1.mga1.src.rpm now available in core/updates_testing.

Assignee: mageia => qa-bugs

Comment 7 Damien Lallement 2012-03-19 16:32:59 CET
Advisory:
This update of pidgin fix CVE-2012-1178 and CVE-2011-4939. It also upgrade to 2.10.2 to allow upgrade from Mandriva 2010.2.

Summary: pidgin new security issue CVE-2012-1178 => pidgin new security issues: CVE-2012-1178 and CVE-2011-4939

Comment 8 Sander Lepik 2012-03-22 12:39:55 CET
Tested on x86_64, seems to work as before.

CC: (none) => sander.lepik

Comment 9 claire robinson 2012-03-22 14:54:17 CET
Tested OK i586. No PoC's.

Validating


Advisory
------------
This update to pidgin fixes two vulnerabilities. It also upgrades to
2.10.2 to allow upgrade from Mandriva 2010.2.

CVE-2012-1178 - The msn_oim_report_to_user function in oim.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.2 allows remote servers to cause a denial of service (application crash) via an OIM message that lacks UTF-8 encoding. 
CVE-2011-4939 - The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1178
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4939
-------------

SRPM: pidgin-2.10.2-1.1.mga1.src.rpm

Could sysadmin please push from core/updates_testing to core/updates

Thanks!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 10 Thomas Backlund 2012-03-24 16:00:33 CET
Update pushed.

Status: ASSIGNED => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED

Comment 11 Frédéric "LpSolit" Buclin 2012-03-26 12:56:16 CEST
Note that 2.10.2 broke the status of MSN buddies, see http://developer.pidgin.im/wiki/ChangeLog

"2.10.3 fixes a problem with MSN buddies appearing online when they shouldn't."

This is a regression in 2.10.2, so people upgrading to this version will be affected by this bug.
Comment 12 David Walser 2012-03-27 01:53:54 CEST
(In reply to comment #11)
> Note that 2.10.2 broke the status of MSN buddies, see
> http://developer.pidgin.im/wiki/ChangeLog
> 
> "2.10.3 fixes a problem with MSN buddies appearing online when they shouldn't."
> 
> This is a regression in 2.10.2, so people upgrading to this version will be
> affected by this bug.

Could you open a new bug report for this?
Frédéric "LpSolit" Buclin 2012-04-27 01:06:00 CEST

Blocks: (none) => 5624


Note You need to log in before you can comment on or make changes to this bug.