|
Message-ID: <CAPZ8mV533aw7Att9pOgH_WSQM=bSx2+2Pp4M7hEYBU4AB5rz2w@mail.gmail.com> Date: Fri, 9 Dec 2011 18:08:19 -0800 From: Mark Doliner <mark@...gant.net> To: oss-security@...ts.openwall.com Subject: CVE request: Pidgin crash Hi! Would it be possible to issue a CVE for a newish crash in Pidgin? This is a remotely-triggerable crash in the oscar protocol (used by the AIM and ICQ plugins) when handling incoming buddy list-related SNACs. I do not believe remote-code execution is possible. It was discovered by Evgeny Boger and reported on our public issue tracker at http://developer.pidgin.im/ticket/14682 I do not believe a CVE exists for this yet. The Pidgin project will be releasing version 2.10.1 tomorrow and it will include a fix for this issue. Thanks (and sorry for sending this at the beginning of your weekends!), Mark
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.