Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAPZ8mV5HBmTNYJKq-pnAWUbTKeZ4cDYNs47zymiCbVagC+A1+g@mail.gmail.com>
Date: Sat, 20 Aug 2011 10:59:50 -0700
From: Mark Doliner <mark@...gant.net>
To: oss-security@...ts.openwall.com
Subject: CVE request: Pidgin crash

Hi!  Would it be possible to issue a CVE for a new crash in Pidgin?

"Certain characters in the nicknames of IRC users can trigger a null
pointer dereference in the IRC protocol plugin's handling of responses
to WHO requests. This can cause a crash on some operating systems.
Clients based on libpurple 2.8.0 through 2.9.0 are affected."
http://pidgin.im/news/security/?id=53

The crash was discovered by Djego Ibanez.

Thanks,
Mark

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.