CVE-2014-3694)Yves Younan and Richard Johnson discovered that Pidgin incorrectly handledcertain malformed MXit emoticons. A malicious remote server or a man in themiddle could use this issue to cause Pidgin to crash, resulting in a denialof service. (CVE-2014-3695)Yves Younan and Richard Johnson discovered that Pidgin incorrectly handledcertain malformed Groupwise messages. A malicious remote server or a man inthe middle could use this issue to cause Pidgin to crash, resulting in adenial of service. (CVE-2014-3696)Thijs Alkemade and Paul Aurich discovered that Pidgin incorrectly handledmemory when processing XMPP messages. A malicious remote server or usercould use this issue to cause Pidgin to disclosure arbitrary memory,resulting in an information leak. (CVE-2014-3698)"> OVAL Reference oval:org.mitre.oval:def:28262 - CERT Civis.Net
Oval Definition:oval:org.mitre.oval:def:28262
Revision Date:2015-03-09Version:6
Title:USN-2390-1 -- Pidgin vulnerabilities
Description:Jacob Appelbaum and an anonymous person discovered that Pidgin incorrectlyhandled certificate validation. A remote attacker could exploit this toperform a man in the middle attack to view sensitive information or alterencrypted communications. (CVE-2014-3694)Yves Younan and Richard Johnson discovered that Pidgin incorrectly handledcertain malformed MXit emoticons. A malicious remote server or a man in themiddle could use this issue to cause Pidgin to crash, resulting in a denialof service. (CVE-2014-3695)Yves Younan and Richard Johnson discovered that Pidgin incorrectly handledcertain malformed Groupwise messages. A malicious remote server or a man inthe middle could use this issue to cause Pidgin to crash, resulting in adenial of service. (CVE-2014-3696)Thijs Alkemade and Paul Aurich discovered that Pidgin incorrectly handledmemory when processing XMPP messages. A malicious remote server or usercould use this issue to cause Pidgin to disclosure arbitrary memory,resulting in an information leak. (CVE-2014-3698)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-3694
CVE-2014-3695
CVE-2014-3696
CVE-2014-3698
USN-2390-1
Platform(s):Ubuntu 12.04
Ubuntu 14.04
Ubuntu 14.10
Product(s):pidgin
Definition Synopsis
  • Ubuntu 14.10 release section
  • Ubuntu 14.10 is installed
  • AND Packages match section
  • pidgin is earlier than 1:2.10.9-0ubuntu7.1
  • OR libpurple0 is earlier than 1:2.10.9-0ubuntu7.1
  • Ubuntu 14.04 release section
  • Ubuntu 14.04 is installed
  • AND Packages match section
  • pidgin is earlier than 1:2.10.9-0ubuntu3.2
  • OR libpurple0 is earlier than 1:2.10.9-0ubuntu3.2
  • Ubuntu 12.04 release section
  • Ubuntu 12.04 is installed
  • AND Packages match section
  • pidgin is earlier than 1:2.10.3-0ubuntu1.6
  • OR libpurple0 is earlier than 1:2.10.3-0ubuntu1.6
  • BACK