PublicDateAtUSN: 2016-06-23 Candidate: CVE-2016-2371 PublicDate: 2017-01-06 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2371 http://www.talosintel.com/reports/TALOS-2016-0139/ http://www.pidgin.im/news/security/?id=104 https://ubuntu.com/security/notices/USN-3031-1 Description: An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution. Ubuntu-Description: Notes: seth-arnold> This patch doesn't enforce upper-limits; it seems insufficient to me. mdeslaur> patch listed in upstream avisory is wrong, it is actually the mdeslaur> fix for CVE-2016-2369 Bugs: Priority: medium Discovered-by: Yves Younan Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_pidgin: upstream: https://bitbucket.org/pidgin/main/commits/f0287378203fbf496a9890bf273d96adefb93b74 upstream_pidgin: released (2.11.0-1) precise_pidgin: released (1:2.10.3-0ubuntu1.7) trusty_pidgin: released (1:2.10.9-0ubuntu3.3) trusty/esm_pidgin: released (1:2.10.9-0ubuntu3.3) vivid/stable-phone-overlay_pidgin: DNE vivid/ubuntu-core_pidgin: DNE wily_pidgin: released (1:2.10.11-0ubuntu4.2) xenial_pidgin: released (1:2.10.12-0ubuntu5.1) devel_pidgin: released (1:2.10.12-0ubuntu6)