Vulnerabilities in Yahoo protocol plugin

John Bailey rekkanoryo at rekkanoryo.org
Sat Mar 5 14:16:50 EST 2011


On 03/05/2011 02:03 PM, John Bailey wrote:
> Hello, packagers,
> 
> Marius Wachtler discovered three remote crash bugs in our Yahoo protocol
> handler.  All three of these are due to improper handling of malformed YMSG
> packets that are missing fields we expect to be present, causing NULL pointer
> dereferences.

I should have mentioned, these bugs have been present since libpurple 2.6.0.

John

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
URL: <http://pidgin.im/cgi-bin/mailman/private/packagers/attachments/20110305/fcc4fc68/attachment.pgp>


More information about the Packagers mailing list