CVE-2011-3594

Publication date 4 November 2011

Last updated 24 July 2024


Ubuntu priority

The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.

Read the notes from the security team

Status

Package Ubuntu Release Status
pidgin 11.10 oneiric
Not affected
11.04 natty
Fixed 1:2.7.11-1ubuntu2.1
10.10 maverick
Fixed 1:2.7.3-1ubuntu3.3
10.04 LTS lucid
Fixed 1:2.6.6-1ubuntu4.4
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

Oneiric+ isn't built with SILC support

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
pidgin

References

Related Ubuntu Security Notices (USN)

    • USN-1273-1
    • Pidgin vulnerabilities
    • 21 November 2011

Other references