First published: Sat Dec 17 2011(Updated: )
The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pidgin | <=2.10.0 | |
Pidgin | =2.0.0 | |
Pidgin | =2.0.1 | |
Pidgin | =2.0.2 | |
Pidgin | =2.1.0 | |
Pidgin | =2.1.1 | |
Pidgin | =2.2.0 | |
Pidgin | =2.2.1 | |
Pidgin | =2.2.2 | |
Pidgin | =2.3.0 | |
Pidgin | =2.3.1 | |
Pidgin | =2.4.0 | |
Pidgin | =2.4.1 | |
Pidgin | =2.4.2 | |
Pidgin | =2.4.3 | |
Pidgin | =2.5.0 | |
Pidgin | =2.5.1 | |
Pidgin | =2.5.2 | |
Pidgin | =2.5.3 | |
Pidgin | =2.5.4 | |
Pidgin | =2.5.5 | |
Pidgin | =2.5.6 | |
Pidgin | =2.5.7 | |
Pidgin | =2.5.8 | |
Pidgin | =2.5.9 | |
Pidgin | =2.6.0 | |
Pidgin | =2.6.1 | |
Pidgin | =2.6.2 | |
Pidgin | =2.6.3 | |
Pidgin | =2.6.4 | |
Pidgin | =2.6.5 | |
Pidgin | =2.6.6 | |
Pidgin | =2.7.1 | |
Pidgin | =2.7.2 | |
Pidgin | =2.7.3 | |
Pidgin | =2.7.4 | |
Pidgin | =2.7.5 | |
Pidgin | =2.7.6 | |
Pidgin | =2.7.7 | |
Pidgin | =2.7.8 | |
Pidgin | =2.7.9 | |
Pidgin | =2.7.10 | |
Pidgin | =2.7.11 | |
Pidgin | =2.8.0 | |
Pidgin | =2.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4603 is categorized as a denial of service vulnerability due to application crashes caused by malformed messages.
To fix CVE-2011-4603, you should update Pidgin to version 2.10.1 or later as it contains the security patch.
If you are using an affected version of Pidgin, your application may be vulnerable to crashes when receiving crafted messages.
CVE-2011-4603 affects all Pidgin versions prior to 2.10.1, including versions from 2.0.0 to 2.10.0.
Yes, after applying the fix by updating to Pidgin version 2.10.1 or later, the vulnerability CVE-2011-4603 should no longer pose a risk.