CVE-2008-1227: Buffer Overflow
Description of problem: pidgin crashes on login to a silc account. I tried setting it up fresh, and from old setup. Both caused the crash.
Version-Release number of selected component (if applicable): pidgin-2.2.2-1.fc8.x8664
How reproducible: Everytime
Steps to Reproduce: 1. Install pidgin 2. Run pidgin 3. Setup silc account Actual results: Crash
Expected results: Runs normally
Additional info: If run from a terminal window it mentions a buffer overflow.
Other sources
Stack-based buffer overflow in the silcfingerprint function in lib/silcutil/silcutil.c in Secure Internet Live Conferencing (SILC) Toolkit 1.1.5, and unspecified earlier versions, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via long input data. NOTE: some of these details are obtained from third party information.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1227?
CVE-2008-1227 has a moderate severity rating due to the potential for the application to crash upon connecting to a silc account.
How do I fix CVE-2008-1227?
To resolve CVE-2008-1227, update to a patched version of the Pidgin software or the Silc Toolkit.
Which versions of Pidgin are affected by CVE-2008-1227?
CVE-2008-1227 affects Pidgin version 2.2.2 and likely earlier versions.
What software does CVE-2008-1227 impact?
CVE-2008-1227 impacts both Pidgin and multiple versions of the Silc Toolkit.
Is there a workaround for CVE-2008-1227?
Currently, there is no known workaround for CVE-2008-1227 aside from updating the affected software.