PublicDateAtUSN: 2010-10-27 Candidate: CVE-2010-3711 PublicDate: 2010-10-28 00:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3711 http://pidgin.im/news/security/?id=48 https://ubuntu.com/security/notices/USN-1014-1 Description: libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/pidgin/+bug/666998 Priority: low Discovered-by: Daniel Atallah Assigned-to: mdeslaur CVSS: Patches_pidgin: upstream: http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcc upstream_pidgin: released (2.7.4-2) dapper_pidgin: DNE hardy_pidgin: released (1:2.4.1-1ubuntu2.10) karmic_pidgin: released (1:2.6.2-1ubuntu7.3) lucid_pidgin: released (1:2.6.6-1ubuntu4.1) maverick_pidgin: released (1:2.7.3-1ubuntu3.1) devel_pidgin: not-affected (1:2.7.9-1ubuntu1)