pidgin crashes with malformed png

Bug #1041141 reported by Jacob Appelbaum
262
This bug affects 2 people
Affects Status Importance Assigned to Milestone
pidgin (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

This is for Pidgin 2.7.11 (libpurple 2.7.11); the package is 'pidgin' version '1:2.7.11-1ubuntu2.2' on Ubuntu Natty.

I originally reported this to the Pidgin developers but it appears to also be related to GTK on Natty. The original bug has a lot of information:
http://developer.pidgin.im/ticket/15282

In short, without just repeating the full pidgin bug, when I attempt to set the following PNG as my buddy icon, pidgin crashes:
http://developer.pidgin.im/attachment/ticket/14571/png-1-width-800-height-2.png

These images may also be of interest:
http://developer.pidgin.im/attachment/ticket/14571/local-buddy-icon.png
http://developer.pidgin.im/attachment/ticket/14571/png-1-width-519-height-2.png

This may also be of interest to the security team - GTK may be the actual issue underlying all of the tickets:
http://developer.pidgin.im/ticket/14571#comment:15

Tags: gtk pidgin
visibility: private → public
Revision history for this message
Sina Rabbani (sina-f) wrote :

The program 'Pidgin' received an X Window System error.
This probably reflects a bug in the program.
The error was 'BadAlloc (insufficient resources for operation)'.
  (Details: serial 24518 error_code 11 request_code 53 minor_code 0)
  (Note to programmers: normally, X errors are reported asynchronously;
   that is, you will receive the error a while after causing it.
   To debug your program, run it with the --sync command line
   option to change this behavior. You can then get a meaningful
   backtrace from your debugger if you break on the gdk_x_error() function.)

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in pidgin (Ubuntu):
status: New → Confirmed
Revision history for this message
Jacob Appelbaum (jacob-appelbaum) wrote :

This bug appears to actually crash the X server - so it's probably a bug in a few things. Please read the pidgin bug to better understand the issue.

Revision history for this message
Tomasz Wasilczyk (tomkiewi) wrote :

It's already fixed with Pidgin 2.10.7.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.