Bug 991709 (CVE-2016-2373) - VUL-0: CVE-2016-2373: pidgin: MXIT Contact Mood Denial of Service Vulnerability
Summary: VUL-0: CVE-2016-2373: pidgin: MXIT Contact Mood Denial of Service Vulnerability
Status: RESOLVED WONTFIX
Alias: CVE-2016-2373
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Felix Zhang
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/170399/
Whiteboard: CVSSv2:SUSE:CVE-2016-2373:4.3:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-02 13:26 UTC by Marcus Meissner
Modified: 2018-07-06 14:37 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-08-02 13:26:00 UTC
rh#1348877

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.

External references:

http://www.talosintel.com/reports/TALOS-2016-0141/
http://www.pidgin.im/news/security/?id=106

Upstream fixes:

https://bitbucket.org/pidgin/main/commits/e6159ad42c4c

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1348877
Comment 1 Marcus Meissner 2016-08-02 13:27:57 UTC
sle11 and sle12 are affected
Comment 2 Swamp Workflow Management 2016-08-02 22:02:27 UTC
bugbot adjusting priority
Comment 3 Felix Zhang 2016-09-14 04:29:36 UTC
SLE11 backport here:
https://build.suse.de/request/show/121073

SLE12SP2 updated to 2.11.0 hence not affected.
Comment 4 Swamp Workflow Management 2016-09-29 17:10:21 UTC
SUSE-SU-2016:2416-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 991691,991709,991711,991712,991715
CVE References: CVE-2016-2367,CVE-2016-2370,CVE-2016-2371,CVE-2016-2372,CVE-2016-2373
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    pidgin-2.6.6-0.29.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    pidgin-2.6.6-0.29.1
Comment 5 Felix Zhang 2018-06-11 13:45:38 UTC
With Mxit officially shut down its services in 2016 and pidgin dropped support to the protocol since 2.12. Efforts to backport the fix won't make much sense.
Discussed with Johannes and decided to close this as WONTFIX.