Pidgin Security Advisory

TitleRemote crash in MSN protocol plugin
Date2011-08-20
CVE NameCVE-2011-3184
Discovered ByMarius Wachtler
DescriptionIncorrect handling of HTTP 100 responses in the MSN protocol plugin can cause the application to attempt to access memory that it does not have access to. This only affects users who have turned on the HTTP connection method for their accounts (it's off by default). This might only be triggerable by a malicious server and not a malicious peer. We believe remote code execution is not possible.
Fixed in Revision2379d8500566
Fixed in Version2.10.0
FixCorrectly take into account the size of HTTP 100 response when parsing server messages.

Return to Security Advisory Index