CVE-2010-3711
CVE-2010-3711
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcchttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/050133.htmlhttp://pidgin.im/news/security/?id=48https://bugzilla.redhat.com/show_bug.cgi?id=641921http://secunia.com/advisories/41893http://secunia.com/advisories/41899http://secunia.com/advisories/42075http://secunia.com/advisories/42294http://securitytracker.com/id?1024623https://exchange.xforce.ibmcloud.com/vulnerabilities/62708