Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAPZ8mV533aw7Att9pOgH_WSQM=bSx2+2Pp4M7hEYBU4AB5rz2w@mail.gmail.com>
Date: Fri, 9 Dec 2011 18:08:19 -0800
From: Mark Doliner <mark@...gant.net>
To: oss-security@...ts.openwall.com
Subject: CVE request: Pidgin crash

Hi!  Would it be possible to issue a CVE for a newish crash in Pidgin?
 This is a remotely-triggerable crash in the oscar protocol (used by
the AIM and ICQ plugins) when handling incoming buddy list-related
SNACs.  I do not believe remote-code execution is possible.  It was
discovered by Evgeny Boger and reported on our public issue tracker at
http://developer.pidgin.im/ticket/14682  I do not believe a CVE exists
for this yet.

The Pidgin project will be releasing version 2.10.1 tomorrow and it
will include a fix for this issue.

Thanks (and sorry for sending this at the beginning of your weekends!),
Mark

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.