CVE-2011-4922
Publication date 4 January 2012
Last updated 24 July 2024
Ubuntu priority
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.
Status
Package | Ubuntu Release | Status |
---|---|---|
pidgin | ||
Patch details
Package | Patch details |
---|---|
pidgin |
References
Related Ubuntu Security Notices (USN)
- USN-1500-1
- Pidgin vulnerabilities
- 9 July 2012