Bug 991691 - (CVE-2016-2371) VUL-0: CVE-2016-2371: pidgin: MXIT Extended Profiles Code Execution Vulnerability
(CVE-2016-2371)
VUL-0: CVE-2016-2371: pidgin: MXIT Extended Profiles Code Execution Vulnerabi...
Status: RESOLVED WONTFIX
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Felix Zhang
Security Team bot
https://smash.suse.de/issue/170397/
CVSSv2:SUSE:CVE-2016-2371:6.8:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-08-02 12:06 UTC by Marcus Meissner
Modified: 2018-07-06 14:37 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-08-02 12:06:22 UTC
rh#1348873

An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

External references:

http://www.talosintel.com/reports/TALOS-2016-0139/
http://www.pidgin.im/news/security/?id=104

Upstream fix:

https://bitbucket.org/pidgin/main/commits/7b52ca213832

https://bugzilla.redhat.com/show_bug.cgi?id=1348873
Comment 1 Marcus Meissner 2016-08-02 12:07:25 UTC
both in sle11 and sle12.
Comment 2 Swamp Workflow Management 2016-08-02 22:01:29 UTC
bugbot adjusting priority
Comment 3 Felix Zhang 2016-09-14 03:05:57 UTC
Backport to SLE11 here:
https://build.suse.de/request/show/121071

SLE12SP2 updated to 2.11.0 hence not affected.
Comment 4 Felix Zhang 2016-09-14 03:16:40 UTC
New SLE11 submission here:
https://build.suse.de/request/show/121072

Use the patch exported from mercurial instead.
Comment 6 Swamp Workflow Management 2016-09-29 17:10:13 UTC
SUSE-SU-2016:2416-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 991691,991709,991711,991712,991715
CVE References: CVE-2016-2367,CVE-2016-2370,CVE-2016-2371,CVE-2016-2372,CVE-2016-2373
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    pidgin-2.6.6-0.29.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    pidgin-2.6.6-0.29.1
Comment 7 Felix Zhang 2018-06-11 13:49:13 UTC
With Mxit officially shut down its services in 2016 and pidgin dropped support to the protocol since 2.12. Efforts to backport the fix won't make much sense.
Discussed with Johannes and decided to close this as WONTFIX.