PublicDate: 2009-05-26 15:30:00 UTC Candidate: CVE-2009-1375 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1375 https://ubuntu.com/security/notices/USN-781-1 Description: The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/bugs/384222 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_pidgin: upstream: http://developer.pidgin.im/viewmtn/revision/info/7829ec76bdb008583f8da54e238c2265a1140db2 upstream_pidgin: released (2.5.6) dapper_pidgin: DNE feisty_pidgin: DNE hardy_pidgin: released (1:2.4.1-1ubuntu2.4) intrepid_pidgin: released (1:2.5.2-0ubuntu1.2) jaunty_pidgin: released (1:2.5.5-1ubuntu8.1) devel_pidgin: not-affected (1:2.5.6-1ubuntu1) Patches_gaim: upstream_gaim: released (2.5.6) dapper_gaim: not-affected (code not present) gutsy_gaim: DNE hardy_gaim: DNE intrepid_gaim: DNE jaunty_gaim: DNE devel_gaim: DNE