Secunia Logo
 
CVE Reference: CVE-2008-2927
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2927

Description:
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

CVE Status:
Candidate

References:

ST
  1020451

SAID
  Secunia Advisory: SA30971
  Secunia Advisory: SA31016
  Secunia Advisory: SA31105
  Secunia Advisory: SA31387
  Secunia Advisory: SA31642

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0584.html

MLIST
  http://www.openwall.com/lists/oss-security/2008/07/04/1
  http://www.openwall.com/lists/oss-security/2008/07/03/6

MISC
  http://www.zerodayinitiative.com/advisories/ZDI-08-054

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:143

DEBIAN
  http://www.debian.org/security/2008/dsa-1610

CONFIRM
  http://www.pidgin.im/news/security/?id=25
  http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0246
  http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msnp9/slplink.c
  http://developer.pidgin.im/viewmtn/revision/diff/6eb1949a96fa80a4c744fc749c2562abc4cc9ed6/with/c3831c9181f4f61b747321240086ee79e4a08fd8/libpurple/protocols/msn/slplink.c

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/495818/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/495165/100/0/threaded
  http://www.securityfocus.com/archive/1/493682

BID
  29956


Return to the previous page.