Bugzilla – Bug 970498
VUL-0: CVE-2015-8833: pidgin-otr: heap use after free vulnerability
Last modified: 2017-04-03 16:04:49 UTC
rh#1316427 The pidgin-otr plugin version 4.0.2 fixes a heap use after free error. The bug is triggered when a user tries to authenticate a buddy and happens in the function create_smp_dialog. External references: https://blog.fuzzing-project.org/39-Heap-use-after-free-in-Pidgin-OTR-plugin.html http://seclists.org/oss-sec/2016/q1/572 Upstream bug report: https://bugs.otr.im/issues/88 Upstream fix: https://bugs.otr.im/projects/pidgin-otr/repository/revisions/aaf551b9dd5cbba8c4abaa3d4dc7ead860efef94 References: https://bugzilla.redhat.com/show_bug.cgi?id=1316427 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8833 http://seclists.org/oss-sec/2016/q1/577
bugbot adjusting priority
https://build.opensuse.org/patchinfo/show/openSUSE:Maintenance:4811/patchinfo For Leap and 13.2
https://build.suse.de/request/show/104549 for SLE12. SLE11 is not vulnerable as it does not perform the check for a different context in create_smp_dialog
openSUSE-SU-2016:0878-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 970498 CVE References: CVE-2015-8833 Sources used: openSUSE Leap 42.1 (src): pidgin-otr-4.0.2-7.1 openSUSE 13.2 (src): pidgin-otr-4.0.2-7.8.1
released
SUSE-SU-2016:0912-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 970498 CVE References: CVE-2015-8833 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP1 (src): pidgin-otr-4.0.0-8.1 SUSE Linux Enterprise Workstation Extension 12 (src): pidgin-otr-4.0.0-8.1 SUSE Linux Enterprise Desktop 12-SP1 (src): pidgin-otr-4.0.0-8.1 SUSE Linux Enterprise Desktop 12 (src): pidgin-otr-4.0.0-8.1 Product List: SUSE Linux Enterprise Workstation Extension 12-SP1 SUSE Linux Enterprise Workstation Extension 12 SUSE Linux Enterprise Desktop 12-SP1 SUSE Linux Enterprise Desktop 12