Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora: 10 Update 2009:7370 Moderate: Pidgin Denial Of Service

fedora
Calendar Grey July 3, 2009
Dist Fedora Esm H88
The recent pidgin update on Fedora 10 brings essential corrections for various messaging protocols and resolves significant problems.
Several important bug fixes: - More fixes for Yahoo protocol 16 - MSN, MySpace, XMPP - CVE-2009-1889

Summary

Pidgin allows you to talk to anyone using a variety of messaging

protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu,

ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and

Zephyr. These protocols are implemented using a modular, easy to

use design. To use a protocol, just add an account using the

account editor.

Pidgin supports many common features of other clients, as well as many

unique features, such as perl scripting, TCL scripting and C plugins.

Pidgin is not affiliated with or endorsed by America Online, Inc.,

Microsoft Corporation, Yahoo! Inc., or ICQ Inc.

Update Information:

Several important bug fixes: - More fixes for Yahoo protocol 16 - MSN, MySpace, XMPP - CVE-2009-1889

Change Log

* Sun Jun 28 2009 Warren Togami 2.5.8-1 - 2.5.8 with several important bug fixes * Mon Jun 22 2009 Warren Togami 2.5.7-2 - glib2 compat with RHEL-4 * Sat Jun 20 2009 Warren Togami 2.5.7-1 - 2.5.7 with Yahoo Protocol 16 support * Wed May 20 2009 Stu Tomlinson 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami 2.5.5-3 - F12+ removed krb4 * Tue Mar 3 2009 Stu Tomlinson 2.5.5-1 - 2.5.5 * Thu Feb 26 2009 Fedora Release Engineering - 2.5.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Tue Jan 27 2009 Warren Togami 2.5.4-2 - one_time_password plugin - Eliminate RPATH * Mon Jan 12 2009 Stu Tomlinson 2.5.4-1 - 2.5.4 * Fri Dec 26 2008 Warren Togami 2.5.3-1 - 2.5.3 * Sat Nov 22 2008 Warren Togami 2.5.2-6 - Automatically detect booleans to enable build features from dist tag - Unify RHEL4 and RHEL5 spec with Fedora to make both easier to maintain * Fri Nov 21 2008 Warren Togami 2.5.2-2 - Upstream backports: 100: sametime-redirect-null crash 101: NetworkManager-improvement 102: no-password-in-dialog-if-not-remembering 103: temporarily-remember-password-during-auto-reconnect 104: smilie-theme-change-crash 105: url_fetch_connect_cb-double-free crash 106: GtkIMHtmlSmileys-remove-crash 107: remove-dialog-from-open-dialog-list

References


[ 1 ] Bug #508738 - CVE-2009-1889 pidgin: DoS via specially-crafted ICQWebMessage https://bugzilla.redhat.com/show_bug.cgi?id=508738

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: pidgin
Product: Fedora 10
Version: 2.5.8
Release: 1.fc10
Summary: A Gtk+ based multiprotocol instant messaging client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here