Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.
{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.10.9-0ubuntu3.4"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.10.9-0ubuntu3.4"
},
{
"binary_name": "libpurple0",
"binary_version": "1:2.10.9-0ubuntu3.4"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.10.9-0ubuntu3.4"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.10.9-0ubuntu3.4"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.10.12-0ubuntu5.2"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.10.12-0ubuntu5.2"
},
{
"binary_name": "libpurple0",
"binary_version": "1:2.10.12-0ubuntu5.2"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.10.12-0ubuntu5.2"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.10.12-0ubuntu5.2"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.12.0-1ubuntu4"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.12.0-1ubuntu4"
},
{
"binary_name": "libpurple0",
"binary_version": "1:2.12.0-1ubuntu4"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.12.0-1ubuntu4"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.12.0-1ubuntu4"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.13.0-2.2ubuntu4"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.13.0-2.2ubuntu4"
},
{
"binary_name": "libpurple0",
"binary_version": "1:2.13.0-2.2ubuntu4"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.13.0-2.2ubuntu4"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.13.0-2.2ubuntu4"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.14.8-1ubuntu2.1"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.14.8-1ubuntu2.1"
},
{
"binary_name": "libpurple0",
"binary_version": "1:2.14.8-1ubuntu2.1"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.14.8-1ubuntu2.1"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.14.8-1ubuntu2.1"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.14.13-1ubuntu2"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.14.13-1ubuntu2"
},
{
"binary_name": "libpurple0t64",
"binary_version": "1:2.14.13-1ubuntu2"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.14.13-1ubuntu2"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.14.13-1ubuntu2"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.14.14-1ubuntu2"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.14.14-1ubuntu2"
},
{
"binary_name": "libpurple0t64",
"binary_version": "1:2.14.14-1ubuntu2"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.14.14-1ubuntu2"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.14.14-1ubuntu2"
}
]
}{
"binaries": [
{
"binary_name": "finch",
"binary_version": "1:2.14.14-1ubuntu3"
},
{
"binary_name": "libpurple-bin",
"binary_version": "1:2.14.14-1ubuntu3"
},
{
"binary_name": "libpurple0t64",
"binary_version": "1:2.14.14-1ubuntu3"
},
{
"binary_name": "pidgin",
"binary_version": "1:2.14.14-1ubuntu3"
},
{
"binary_name": "pidgin-data",
"binary_version": "1:2.14.14-1ubuntu3"
}
]
}