PublicDateAtUSN: 2014-02-05 Candidate: CVE-2012-6152 PublicDate: 2014-02-06 16:10:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6152 http://www.pidgin.im/news/security/?id=70 https://ubuntu.com/security/notices/USN-2100-1 Description: The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Thijs Alkemade and Robert Vehse Assigned-to: mdeslaur CVSS: Patches_pidgin: upstream: http://hg.pidgin.im/pidgin/main/rev/b0345c25f886 upstream_pidgin: released (2.10.8) lucid_pidgin: ignored (reached end-of-life) precise_pidgin: released (1:2.10.3-0ubuntu1.4) quantal_pidgin: released (1:2.10.6-0ubuntu2.3) saucy_pidgin: released (1:2.10.7-0ubuntu4.1.13.10.1) devel_pidgin: released (1:2.10.9-0ubuntu1)