Bug 970498 (CVE-2015-8833) - VUL-0: CVE-2015-8833: pidgin-otr: heap use after free vulnerability
Summary: VUL-0: CVE-2015-8833: pidgin-otr: heap use after free vulnerability
Status: RESOLVED FIXED
Alias: CVE-2015-8833
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/163005/
Whiteboard: CVSSv2:RedHat:CVE-2015-8833:5.0:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-03-10 14:45 UTC by Victor Pereira
Modified: 2017-04-03 16:04 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2016-03-10 14:45:57 UTC
rh#1316427

The pidgin-otr plugin version 4.0.2 fixes a heap use after free error. The bug is triggered when a user tries to authenticate a buddy and happens in the function create_smp_dialog.

External references:

https://blog.fuzzing-project.org/39-Heap-use-after-free-in-Pidgin-OTR-plugin.html
http://seclists.org/oss-sec/2016/q1/572

Upstream bug report:

https://bugs.otr.im/issues/88

Upstream fix:

https://bugs.otr.im/projects/pidgin-otr/repository/revisions/aaf551b9dd5cbba8c4abaa3d4dc7ead860efef94

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1316427
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8833
http://seclists.org/oss-sec/2016/q1/577
Comment 1 Swamp Workflow Management 2016-03-10 23:00:42 UTC
bugbot adjusting priority
Comment 4 Scott Reeves 2016-03-21 21:21:29 UTC
https://build.suse.de/request/show/104549 for SLE12.

SLE11 is not vulnerable as it does not perform the check for a different context in create_smp_dialog
Comment 5 Swamp Workflow Management 2016-03-24 14:11:05 UTC
openSUSE-SU-2016:0878-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 970498
CVE References: CVE-2015-8833
Sources used:
openSUSE Leap 42.1 (src):    pidgin-otr-4.0.2-7.1
openSUSE 13.2 (src):    pidgin-otr-4.0.2-7.8.1
Comment 6 Marcus Meissner 2016-03-30 14:31:59 UTC
released
Comment 7 Swamp Workflow Management 2016-04-01 11:03:21 UTC
SUSE-SU-2016:0912-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 970498
CVE References: CVE-2015-8833
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    pidgin-otr-4.0.0-8.1
SUSE Linux Enterprise Workstation Extension 12 (src):    pidgin-otr-4.0.0-8.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    pidgin-otr-4.0.0-8.1
SUSE Linux Enterprise Desktop 12 (src):    pidgin-otr-4.0.0-8.1

Product List: SUSE Linux Enterprise Workstation Extension 12-SP1
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Desktop 12-SP1
SUSE Linux Enterprise Desktop 12