Oval Definition:oval:com.ubuntu.precise:def:20114922000
Revision Date:2012-08-08Version:1
Title:CVE-2011-4922 on Ubuntu 12.04 LTS (precise) - low.
Description:cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2011-4922
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'pidgin' package in precise is not affected (note: '1:2.10.1-1ubuntu1').
  • BACK