Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
BID:54322
Info
Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 54322 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-3374 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2012 12:00AM |
| Updated: | Apr 13 2015 09:34PM |
| Credit: | Ulf Härnhammar |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 91.D2.32 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 73.D2.33 Xerox FreeFlow Print Server (FFPS) 73.C5.11 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 SuSE Suse Linux Enterprise Desktop 11 SP2 SuSE Suse Linux Enterprise Desktop 11 SP1 SuSE Suse Linux Enterprise Desktop 10 SP4 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux -current Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Pidgin Pidgin 2.10.4 Pidgin Pidgin 2.10.3 Pidgin Pidgin 2.10.2 Pidgin Pidgin 2.10.1 Pidgin Pidgin 2.9 Pidgin Pidgin 2.8 Pidgin Pidgin 2.7.6 Pidgin Pidgin 2.7.5 Pidgin Pidgin 2.7.4 Pidgin Pidgin 2.7.3 Pidgin Pidgin 2.7.2 Pidgin Pidgin 2.7.1 Pidgin Pidgin 2.7 Pidgin Pidgin 2.6.6 Pidgin Pidgin 2.6.5 Pidgin Pidgin 2.6.4 Pidgin Pidgin 2.6.3 Pidgin Pidgin 2.6.1 Pidgin Pidgin 2.6 Pidgin Pidgin 2.5.9 Pidgin Pidgin 2.5.8 Pidgin Pidgin 2.5.7 Pidgin Pidgin 2.5.6 Pidgin Pidgin 2.5.5 Pidgin Pidgin 2.4.3 Pidgin Pidgin 2.4.2 Pidgin Pidgin 2.4.1 Pidgin Pidgin 2.4 Pidgin Pidgin 2.2.2 Pidgin Pidgin 2.2.1 Pidgin Pidgin 2.2 Pidgin Pidgin 2.1 Pidgin Pidgin 2.0.2 Pidgin Pidgin 2.0 Pidgin Pidgin 2.10.2 Pidgin Pidgin 2.10.0 Pidgin Pidgin 0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Pidgin Pidgin 2.10.5 |
Discussion
Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
Pidgin is prone to a stack-based buffer-overflow vulnerability.
Successful exploits of the buffer-overflow issue may lead to the execution of arbitrary code in the context of the application or to denial-of-service conditions.
Versions prior to Pidgin 2.10.5 vulnerable.
Pidgin is prone to a stack-based buffer-overflow vulnerability.
Successful exploits of the buffer-overflow issue may lead to the execution of arbitrary code in the context of the application or to denial-of-service conditions.
Versions prior to Pidgin 2.10.5 vulnerable.
Exploit / POC
Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Slackware Linux -current
Slackware Linux 12.2
Slackware Linux 13.1 x86_64
Slackware Linux 13.1
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.0 x86_64
Solution:
Vendor updates are available. Please see the references for more information.
Slackware Linux -current
-
Slackware pidgin-2.10.6-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ pidgin-2.10.6-i486-1.txz
Slackware Linux 12.2
-
Slackware pidgin-2.10.6-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ pidgin-2.10.6-i486-1_slack12.2.tgz
Slackware Linux 13.1 x86_64
-
Slackware pidgin-2.10.6-x86_64-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/package s/pidgin-2.10.6-x86_64-1_slack13.1.txz
Slackware Linux 13.1
-
Slackware pidgin-2.10.6-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ pidgin-2.10.6-i486-1_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware pidgin-2.10.6-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ xap/pidgin-2.10.6-x86_64-1.txz
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva finch-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64finch0-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64purple-devel-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64purple0-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-bonjour-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-client-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-gevolution-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-i18n-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-meanwhile-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-perl-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-plugins-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-silc-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-tcl-2.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva finch-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libfinch0-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpurple-devel-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpurple0-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-bonjour-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-client-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-gevolution-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-i18n-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-meanwhile-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-perl-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-plugins-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-silc-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva pidgin-tcl-2.10.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.0 x86_64
-
Slackware pidgin-2.10.6-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/pidgin-2.10.6-x86_64-1_slack13.0.txz
References
Pidgin 'mxit_show_message()' Function Stack-Based Buffer Overflow Vulnerability
References:
References:
- Pidgin Homepage (Pidgin)
- Pidgin Security Advisory CVE-2012-3374 (Pidgin)
- Xerox Security Bulletin XRX13-007 (Xerox)