Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 11: 2009-7359 Critical: Pidgin Protocol Fixes for DoS

fedora
Calendar Grey July 3, 2009
Dist Fedora Esm H88
Pidgin version 2.7.0 on Fedora 11 has been patched for notable bugs affecting key messaging protocols such as Yahoo and MSN. This update is vital for maintaining security.
Several important bug fixes: - More fixes for Yahoo protocol 16 - MSN, MySpace, XMPP - CVE-2009-1889

Summary

Pidgin allows you to talk to anyone using a variety of messaging

protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu,

ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and

Zephyr. These protocols are implemented using a modular, easy to

use design. To use a protocol, just add an account using the

account editor.

Pidgin supports many common features of other clients, as well as many

unique features, such as perl scripting, TCL scripting and C plugins.

Pidgin is not affiliated with or endorsed by America Online, Inc.,

Microsoft Corporation, Yahoo! Inc., or ICQ Inc.

Update Information:

Several important bug fixes: - More fixes for Yahoo protocol 16 - MSN, MySpace, XMPP - CVE-2009-1889

Change Log

* Sun Jun 28 2009 Warren Togami 2.5.8-1 - 2.5.8 with several important bug fixes * Mon Jun 22 2009 Warren Togami 2.5.7-2 - glib2 compat with RHEL-4 * Sat Jun 20 2009 Warren Togami 2.5.7-1 - 2.5.7 with Yahoo Protocol 16 support * Wed May 20 2009 Stu Tomlinson 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami 2.5.5-3 - F12+ removed krb4

References


[ 1 ] Bug #508738 - CVE-2009-1889 pidgin: DoS via specially-crafted ICQWebMessage https://bugzilla.redhat.com/show_bug.cgi?id=508738

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pidgin
Product: Fedora 11
Version: 2.5.8
Release: 1.fc11
Summary: A Gtk+ based multiprotocol instant messaging client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here