English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 89547 CVE descriptions
and 49323 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66406
Category:Mandrake Local Security Checks
Title:Mandriva Security Advisory MDVSA-2009:321 (pidgin)
Summary:Mandriva Security Advisory MDVSA-2009:321 (pidgin)
Description:Description:
The remote host is missing an update to pidgin
announced via advisory MDVSA-2009:321.

For details on the issues addressed with this update, please
visit the referenced security advisories.

Affected: 2008.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2009:321
http://pidgin.im/news/security/

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-3532
http://developer.pidgin.im/attachment/ticket/6500/nss-cert-verify.patch
http://www.mandriva.com/security/advisories?name=MDVSA-2009:025
http://www.redhat.com/support/errata/RHSA-2008-1023.html
http://www.ubuntu.com/usn/USN-675-1
BugTraq ID: 30553
http://www.securityfocus.com/bid/30553
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10979
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18327
http://secunia.com/advisories/32859
http://www.vupen.com/english/advisories/2008/2318
http://secunia.com/advisories/31390
http://secunia.com/advisories/33102
XForce ISS Database: pidgin-ssl-spoofing(44220)
http://xforce.iss.net/xforce/xfdb/44220
Common Vulnerability Exposure (CVE) ID: CVE-2008-2955
Bugtraq: 20080625 Pidgin 2.4.1 Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/archive/1/493682/100/0/threaded
BugTraq ID: 29985
http://www.securityfocus.com/bid/29985
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10131
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18050
http://www.vupen.com/english/advisories/2008/1947
http://secunia.com/advisories/30881
http://securityreason.com/securityalert/3966
Common Vulnerability Exposure (CVE) ID: CVE-2008-2957
http://crisp.cs.du.edu/?q=ca2007-1
http://www.openwall.com/lists/oss-security/2008/06/27/3
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9076
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:17599
Common Vulnerability Exposure (CVE) ID: CVE-2009-1373
Debian Security Information: DSA-1805 (Google Search)
http://debian.org/security/2009/dsa-1805
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html
http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:140
http://www.mandriva.com/security/advisories?name=MDVSA-2009:173
http://www.redhat.com/support/errata/RHSA-2009-1059.html
http://www.redhat.com/support/errata/RHSA-2009-1060.html
http://www.ubuntu.com/usn/USN-781-1
http://www.ubuntu.com/usn/USN-781-2
BugTraq ID: 35067
http://www.securityfocus.com/bid/35067
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9005
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:17722
http://secunia.com/advisories/35194
http://secunia.com/advisories/35202
http://secunia.com/advisories/35188
http://secunia.com/advisories/35215
http://secunia.com/advisories/35294
http://secunia.com/advisories/35329
http://secunia.com/advisories/35330
http://www.vupen.com/english/advisories/2009/1396
XForce ISS Database: pidgin-xmppsocks5-bo(50682)
http://xforce.iss.net/xforce/xfdb/50682
Common Vulnerability Exposure (CVE) ID: CVE-2009-1374
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11654
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18201
XForce ISS Database: pidgin-decryptout-bo(50684)
http://xforce.iss.net/xforce/xfdb/50684
Common Vulnerability Exposure (CVE) ID: CVE-2009-1375
http://osvdb.org/54649
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10829
XForce ISS Database: pidgin-purplecircbuffer-dos(50683)
http://xforce.iss.net/xforce/xfdb/50683
Common Vulnerability Exposure (CVE) ID: CVE-2008-2927
http://www.securityfocus.com/archive/1/493682
Bugtraq: 20080806 rPSA-2008-0246-1 gaim (Google Search)
http://www.securityfocus.com/archive/1/archive/1/495165/100/0/threaded
Bugtraq: 20080828 ZDI-08-054: Multiple Vendor libpurple MSN Protocol SLP Message Heap Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/archive/1/495818/100/0/threaded
http://www.openwall.com/lists/oss-security/2008/07/04/1
http://www.openwall.com/lists/oss-security/2008/07/03/6
http://www.zerodayinitiative.com/advisories/ZDI-08-054
Debian Security Information: DSA-1610 (Google Search)
http://www.debian.org/security/2008/dsa-1610
http://www.mandriva.com/security/advisories?name=MDVSA-2008:143
http://www.mandriva.com/security/advisories?name=MDVSA-2009:127
http://www.redhat.com/support/errata/RHSA-2008-0584.html
http://www.ubuntu.com/usn/USN-675-2
BugTraq ID: 29956
http://www.securityfocus.com/bid/29956
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11695
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:17972
http://secunia.com/advisories/32861
http://www.vupen.com/english/advisories/2008/2032/references
http://www.securitytracker.com/id?1020451
http://secunia.com/advisories/30971
http://secunia.com/advisories/31016
http://secunia.com/advisories/31105
http://secunia.com/advisories/31387
http://secunia.com/advisories/31642
XForce ISS Database: adium-msnprotocol-code-execution(44774)
http://xforce.iss.net/xforce/xfdb/44774
Common Vulnerability Exposure (CVE) ID: CVE-2009-1376
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10476
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:18432
http://secunia.com/advisories/37071
XForce ISS Database: pidgin-msn-slp-bo(50680)
http://xforce.iss.net/xforce/xfdb/50680
Common Vulnerability Exposure (CVE) ID: CVE-2009-1889
http://pidgin.im/pipermail/devel/2009-May/008227.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00176.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00228.html
http://www.redhat.com/support/errata/RHSA-2009-1139.html
http://www.ubuntu.com/usn/USN-796-1
BugTraq ID: 35530
http://www.securityfocus.com/bid/35530
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10004
http://secunia.com/advisories/35697
http://secunia.com/advisories/35706
http://secunia.com/advisories/35693
http://www.vupen.com/english/advisories/2009/1749
XForce ISS Database: pidgin-oscar-dos(51448)
http://xforce.iss.net/xforce/xfdb/51448
Common Vulnerability Exposure (CVE) ID: CVE-2009-2694
http://www.exploit-db.com/exploits/9615
http://www.coresecurity.com/content/libpurple-arbitrary-write
Debian Security Information: DSA-1870 (Google Search)
http://www.debian.org/security/2009/dsa-1870
RedHat Security Advisories: RHSA-2009:1218
https://rhn.redhat.com/errata/RHSA-2009-1218.html
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266908-1
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10319
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6320
http://secunia.com/advisories/36384
http://secunia.com/advisories/36392
http://secunia.com/advisories/36401
http://secunia.com/advisories/36402
http://secunia.com/advisories/36708
http://www.vupen.com/english/advisories/2009/2303
http://www.vupen.com/english/advisories/2009/2663
Common Vulnerability Exposure (CVE) ID: CVE-2009-3025
http://www.openwall.com/lists/oss-security/2009/08/19/2
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6167
XForce ISS Database: pidgin-unspecified-dos(52994)
http://xforce.iss.net/xforce/xfdb/52994
Common Vulnerability Exposure (CVE) ID: CVE-2009-3026
http://www.openwall.com/lists/oss-security/2009/08/24/2
BugTraq ID: 36368
http://www.securityfocus.com/bid/36368
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11070
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5757
XForce ISS Database: pidgin-libpurple-weak-security(53000)
http://xforce.iss.net/xforce/xfdb/53000
Common Vulnerability Exposure (CVE) ID: CVE-2009-2703
BugTraq ID: 36277
http://www.securityfocus.com/bid/36277
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11379
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6435
http://secunia.com/advisories/36601
Common Vulnerability Exposure (CVE) ID: CVE-2009-3083
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11852
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6322
Common Vulnerability Exposure (CVE) ID: CVE-2009-3084
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6338
Common Vulnerability Exposure (CVE) ID: CVE-2009-3085
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11223
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6434
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

This is only one of 49323 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Developer APIs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2016 E-Soft Inc. All rights reserved.