Ubuntu 8.04 LTS / 8.10 / 9.04 : pidgin vulnerabilities (USN-781-1)

Ubuntu Security Notice (C) 2009-2016 Canonical, Inc. / NASL script (C) 2009-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related
patches.

Description :

It was discovered that Pidgin did not properly handle certain
malformed messages when sending a file using the XMPP protocol
handler. If a user were tricked into sending a file, a remote attacker
could send a specially crafted response and cause Pidgin to crash, or
possibly execute arbitrary code with user privileges. (CVE-2009-1373)

It was discovered that Pidgin did not properly handle certain
malformed messages in the QQ protocol handler. A remote attacker could
send a specially crafted message and cause Pidgin to crash. This issue
only affected Ubuntu 8.10 and 9.04. (CVE-2009-1374)

It was discovered that Pidgin did not properly handle certain
malformed messages in the XMPP and Sametime protocol handlers. A
remote attacker could send a specially crafted message and cause
Pidgin to crash. (CVE-2009-1375)

It was discovered that Pidgin did not properly handle certain
malformed messages in the MSN protocol handler. A remote attacker
could send a specially crafted message and possibly execute arbitrary
code with user privileges. (CVE-2009-1376).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 39312 ()

Bugtraq ID: 35067

CVE ID: CVE-2009-1373
CVE-2009-1374
CVE-2009-1375
CVE-2009-1376

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial