Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66123
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2009:1536
Summary:The remote host is missing updates announced in;advisory RHSA-2009:1536.;;Pidgin is an instant messaging program which can log in to multiple;accounts on multiple instant messaging networks simultaneously. The AOL;Open System for Communication in Realtime (OSCAR) protocol is used by the;AOL ICQ and AIM instant messaging systems.;;An invalid pointer dereference bug was found in the way the Pidgin OSCAR;protocol implementation processed lists of contacts. A remote attacker;could send a specially-crafted contact list to a user running Pidgin,;causing Pidgin to crash. (CVE-2009-3615);;These packages upgrade Pidgin to version 2.6.3. Refer to the Pidgin release;notes for a full list of changes.;;All Pidgin users should upgrade to these updated packages, which correct;this issue. Pidgin must be restarted for this update to take effect.
Description:Summary:
The remote host is missing updates announced in
advisory RHSA-2009:1536.

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for Communication in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

An invalid pointer dereference bug was found in the way the Pidgin OSCAR
protocol implementation processed lists of contacts. A remote attacker
could send a specially-crafted contact list to a user running Pidgin,
causing Pidgin to crash. (CVE-2009-3615)

These packages upgrade Pidgin to version 2.6.3. Refer to the Pidgin release
notes for a full list of changes.

All Pidgin users should upgrade to these updated packages, which correct
this issue. Pidgin must be restarted for this update to take effect.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3615
36719
http://www.securityfocus.com/bid/36719
37017
http://secunia.com/advisories/37017
37072
http://secunia.com/advisories/37072
ADV-2009-2949
http://www.vupen.com/english/advisories/2009/2949
ADV-2009-2951
http://www.vupen.com/english/advisories/2009/2951
ADV-2010-1020
http://www.vupen.com/english/advisories/2010/1020
MDVSA-2010:085
http://www.mandriva.com/security/advisories?name=MDVSA-2010:085
http://developer.pidgin.im/ticket/10481
http://developer.pidgin.im/viewmtn/revision/info/781682333aea0c801d280c3507ee25552a60bfc0
http://developer.pidgin.im/wiki/ChangeLog
http://www.pidgin.im/news/security/?id=41
oval:org.mitre.oval:def:18388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18388
oval:org.mitre.oval:def:9414
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9414
pidgin-oscar-protocol-dos(53807)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53807
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.