libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
BID:52175
Info
libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
| Bugtraq ID: | 52175 |
| Class: | Design Error |
| CVE: |
CVE-2012-1257 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2012 12:00AM |
| Updated: | Mar 19 2015 08:17AM |
| Credit: | Dimitris Glynos |
| Vulnerable: |
Pidgin Pidgin 2.9 Pidgin Pidgin 2.8 Pidgin Pidgin 2.7.6 Pidgin Pidgin 2.7.5 Pidgin Pidgin 2.7.4 Pidgin Pidgin 2.7.3 Pidgin Pidgin 2.7.2 Pidgin Pidgin 2.7.1 Pidgin Pidgin 2.7 Pidgin Pidgin 2.6.6 Pidgin Pidgin 2.6.5 Pidgin Pidgin 2.6.4 Pidgin Pidgin 2.6.3 Pidgin Pidgin 2.6.1 Pidgin Pidgin 2.6 Pidgin Pidgin 2.5.9 Pidgin Pidgin 2.5.8 Pidgin Pidgin 2.5.7 Pidgin Pidgin 2.5.6 Pidgin Pidgin 2.5.5 Pidgin Pidgin 2.4.3 Pidgin Pidgin 2.4.2 Pidgin Pidgin 2.4.1 Pidgin Pidgin 2.4 Pidgin Pidgin 2.2.2 Pidgin Pidgin 2.2.1 Pidgin Pidgin 2.2 Pidgin Pidgin 2.1 Pidgin Pidgin 2.0.2 Pidgin Pidgin 2.0 Pidgin Pidgin 2.10.0 Pidgin Libpurple 2.8.10 Pidgin Libpurple 2.8.9 Pidgin Libpurple 2.8 Pidgin Libpurple 2.7.11 Pidgin Libpurple 2.7.10 Pidgin Libpurple 2.7.9 Pidgin Libpurple 2.7.7 Pidgin Libpurple 2.7.6 Pidgin Libpurple 2.7.4 Pidgin Libpurple 2.7.3 Pidgin Libpurple 2.7.2 Pidgin Libpurple 2.7 Pidgin Libpurple 2.6.5 Pidgin Libpurple 2.6.4 Pidgin Libpurple 2.6.1 Pidgin Libpurple 2.6 Pidgin Libpurple 2.5.8 Pidgin Libpurple 2.5.6 Pidgin Libpurple 2.5.5 Pidgin Libpurple 2.5.2 Pidgin Libpurple 2.4.3 Pidgin Libpurple 2.4.2 Pidgin Libpurple 2.9.0 Pidgin Libpurple 2.8.2 Pidgin Libpurple 2.8.1 Pidgin Libpurple 2.8.0 Pidgin Libpurple 2.7.9 Pidgin Libpurple 2.7.8 Pidgin Libpurple 2.7.5 Pidgin Libpurple 2.7.1 Pidgin Libpurple 2.6.6 Pidgin Libpurple 2.6.3 Pidgin Libpurple 2.6.2 Pidgin Libpurple 2.5.9 Pidgin Libpurple 2.5.7 Pidgin Libpurple 2.5.4 Pidgin Libpurple 2.5.3 Pidgin Libpurple 2.5.1 Pidgin Libpurple 2.5.0 Pidgin Libpurple 2.4.1 Pidgin Libpurple 2.4.0 Pidgin Libpurple 2.3.1 Pidgin Libpurple 2.3.0 Pidgin Libpurple 2.2.2 Pidgin Libpurple 2.2.1 Pidgin Libpurple 2.2.0 Pidgin Libpurple 2.10.0 Pidgin Libpurple 2.1.1 Pidgin Libpurple 2.1.0 Pidgin Libpurple 2.0.2 Pidgin Libpurple 2.0.1 Pidgin Libpurple 2.0.0 Pidgin Libpurple 1.0 Pidgin Libpurple - |
| Not Vulnerable: |
Pidgin Pidgin 2.10.1 Pidgin Libpurple 2.10.1 |
Discussion
libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
libpurple is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
The following products are vulnerable:
libpurple versions prior to 2.10.1
pidgin versions prior to 2.10.1
pidgin-otr versions prior to 3.2.0
libpurple is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
The following products are vulnerable:
libpurple versions prior to 2.10.1
pidgin versions prior to 2.10.1
pidgin-otr versions prior to 3.2.0
Exploit / POC
libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libpurple CVE-2012-1257 OTR Information Disclosure Vulnerability
References:
References:
- dbus information leakage (pidgin)
- libpurple OTR information leakage (census-labs)
- Pidgin Homepage (Pidgin)