Various buffer overruns in coverity scan

Daniel Atallah datallah at pidgin.im
Thu Oct 18 16:48:07 EDT 2012


I've noticed a couple buffer overruns, the most serious being CID
732103, which I believe can be triggered by a malicious user with a
AIM direct connect session.

There are also some significant issues with the mxit prpl's http handling.

Would we get separate CVEs for these (and anything else), or come up
with a general 2.10.7 CVE for this class of issues?

-D


More information about the security mailing list