Bugzilla – Bug 991718
VUL-0: CVE-2016-2380: pidgin: MXIT mxit_convert_markup_tx Information Leak Vulnerability
Last modified: 2020-11-10 21:20:13 UTC
rh#1348856 An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out of bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read. External references: http://www.talosintel.com/reports/TALOS-2016-0123/ http://www.pidgin.im/news/security/?id=96 Upstream fix: https://bitbucket.org/pidgin/main/commits/8172584fd640 References: https://bugzilla.redhat.com/show_bug.cgi?id=1348856
is in sle11 and sle12.
bugbot adjusting priority
With Mxit officially shut down its services in 2016 and pidgin dropped support to the protocol since 2.12. Efforts to backport the fix won't make much sense. Discussed with Johannes and decided to close this as WONTFIX.