CVE-2012-2214

Publication date 3 July 2012

Last updated 24 July 2024


Ubuntu priority

proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests.

Read the notes from the security team

Status

Package Ubuntu Release Status
pidgin 12.04 LTS precise
Fixed 1:2.10.3-0ubuntu1.1
11.10 oneiric
Fixed 1:2.10.0-0ubuntu2.1
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


jdstrand

claimed to be fixed in 2.10.4


tyhicks

After my code review and upstream's confirmation, the vulnerability was introduced sometime after 2.7.11. Upstream believes it was introduced in changeset 31742:e6eb15f2734b

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
pidgin

References

Related Ubuntu Security Notices (USN)

Other references