slp.c in the MSN protocol plugin in libpurple in Pidgin...
Vulnerability Description
slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-0277
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.html
- http://www.securityfocus.com/bid/38294
- https://rhn.redhat.com/errata/RHSA-2010-0115.html
- http://www.vupen.com/english/advisories/2010/0413
- http://secunia.com/advisories/38563
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:085
- http://www.ubuntu.com/usn/USN-902-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9421
- http://secunia.com/advisories/38640
- http://secunia.com/advisories/38658
- http://secunia.com/advisories/41868
- https://bugzilla.redhat.com/show_bug.cgi?id=554335
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.html
- http://www.vupen.com/english/advisories/2010/1020
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.html
- http://secunia.com/advisories/38712
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18348
- http://www.vupen.com/english/advisories/2010/2693
- http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
- http://pidgin.im/news/security/?id=43
- http://blogs.sun.com/security/entry/cve_2010_0277_malformed_msn
- http://www.openwall.com/lists/oss-security/2010/01/07/2
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:041
- http://secunia.com/advisories/38915
- http://developer.pidgin.im/wiki/ChangeLog
More from adium
View All →Affected Vendor
adium
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.