CVE-2009-2703

Publication date 8 September 2009

Last updated 24 July 2024


Ubuntu priority

libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.

Read the notes from the security team

Status

Package Ubuntu Release Status
pidgin 9.10 karmic
Not affected
9.04 jaunty
Fixed 1:2.5.5-1ubuntu8.5
8.10 intrepid
Fixed 1:2.5.2-0ubuntu1.6
8.04 LTS hardy
Fixed 1:2.4.1-1ubuntu2.8
6.06 LTS dapper Not in release

Notes


mdeslaur

PoC in Red Hat bug

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
pidgin