Remote crash in ICQ

Warren Togami wtogami at redhat.com
Sat Jun 27 17:43:22 EDT 2009


Do we need a CVE number for this?

On 06/27/2009 02:27 PM, John Bailey wrote:
> Hi, everyone.
>
> Here is a patch that I committed for the upcoming Pidgin 2.5.8 that fixes a
> remote crash.  If an ICQ user sends a web message to a libpurple user, the
> message can be misparsed as being an SMS message, thus causing an excessively
> large allocation.  The attached patch corrects that and makes some other minor
> tweaks.
>
> The bug was discovered by Yuriy Kaminskiy.  This patch is a combination of four
> related patches he submitted to fix this bug.
>
> John



More information about the Packagers mailing list