CVE-2008-2927

Publication date 7 July 2008

Last updated 24 July 2024


Ubuntu priority

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

Status

Package Ubuntu Release Status

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details

References

Related Ubuntu Security Notices (USN)

    • USN-675-1
    • Pidgin vulnerabilities
    • 24 November 2008
    • USN-675-2
    • Gaim vulnerability
    • 24 November 2008

Other references