CVE-2011-1091

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pidgin:pidgin:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.6.5:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.6.6:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.6:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.7:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.8:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.9:*:*:*:*:*:*:*
cpe:2.3:a:pidgin:pidgin:2.7.10:*:*:*:*:*:*:*

History

13 Feb 2023, 04:29

Type Values Removed Values Added
Summary CVE-2011-1091 Pidgin: Multiple NULL pointer dereference flaws in Yahoo protocol plug-in libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2011:1371', 'name': 'https://access.redhat.com/errata/RHSA-2011:1371', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2011-1091', 'name': 'https://access.redhat.com/security/cve/CVE-2011-1091', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2011:0616', 'name': 'https://access.redhat.com/errata/RHSA-2011:0616', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 17:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2011:1371 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2011-1091 -
  • (MISC) https://access.redhat.com/errata/RHSA-2011:0616 -
Summary libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message. CVE-2011-1091 Pidgin: Multiple NULL pointer dereference flaws in Yahoo protocol plug-in

Information

Published : 2011-03-14 19:55

Updated : 2023-12-10 11:03


NVD link : CVE-2011-1091

Mitre link : CVE-2011-1091

CVE.ORG link : CVE-2011-1091


JSON object : View

Products Affected

pidgin

  • pidgin