Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 9: 2009-5552 Critical Pidgin Buffer Overflow Security Fix

fedora
Calendar Grey June 2, 2009
Dist Fedora Esm H88
Pidgin 2.5.6 rolls out essential patches and security enhancements to tackle various weaknesses in Fedora 9.
This is a bugfix & security fix release of Pidgin

Summary

Pidgin allows you to talk to anyone using a variety of messaging

protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu,

ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and

Zephyr. These protocols are implemented using a modular, easy to

use design. To use a protocol, just add an account using the

account editor.

Pidgin supports many common features of other clients, as well as many

unique features, such as perl scripting, TCL scripting and C plugins.

Pidgin is not affiliated with or endorsed by America Online, Inc.,

Microsoft Corporation, Yahoo! Inc., or ICQ Inc.

Update Information:

This is a bugfix & security fix release of Pidgin. The full ChangeLog is available at http://developer.pidgin.im/wiki/ChangeLog Details of the security fixes included are available at

Change Log

* Wed May 20 2009 Stu Tomlinson 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami 2.5.5-3 - F12+ removed krb4 * Tue Mar 3 2009 Stu Tomlinson 2.5.5-1 - 2.5.5 * Thu Feb 26 2009 Fedora Release Engineering - 2.5.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Tue Jan 27 2009 Warren Togami 2.5.4-2 - one_time_password plugin - Eliminate RPATH * Mon Jan 12 2009 Stu Tomlinson 2.5.4-1 - 2.5.4 * Fri Dec 26 2008 Warren Togami 2.5.3-1 - 2.5.3 * Sat Nov 22 2008 Warren Togami 2.5.2-6 - Automatically detect booleans to enable build features from dist tag - Unify RHEL4 and RHEL5 spec with Fedora to make both easier to maintain * Fri Nov 21 2008 Warren Togami 2.5.2-2 - Upstream backports: 100: sametime-redirect-null crash 101: NetworkManager-improvement 102: no-password-in-dialog-if-not-remembering 103: temporarily-remember-password-during-auto-reconnect 104: smilie-theme-change-crash 105: url_fetch_connect_cb-double-free crash 106: GtkIMHtmlSmileys-remove-crash 107: remove-dialog-from-open-dialog-list * Mon Oct 20 2008 Stu Tomlinson 2.5.2-1 - 2.5.2 - Generate doxygen API documentation (#466693) * Tue Sep 16 2008 Stu Tomlinson 2.5.1-3 - Backport fixes from upstream: Add "Has You:" back to MSN tooltips Fix crash during removal of your own buddy icon Fix crash when handling self signed certificate with NSS SSL * Tue Sep 16 2008 Stu Tomlinson 2.5.1-2 - Fix a crash with GNOME proxy enabled (#461951) * Sun Aug 31 2008 Stu Tomlinson 2.5.1-1 - 2.5.1 * Sat Aug 23 2008 Stu Tomlinson 2.5.0-1 - 2.5.0 * Tue Jul 1 2008 Stu Tomlinson 2.4.3-1.1 - Add a patch to build with latest rawhide tcl * Tue Jul 1 2008 Stu Tomlinson 2.4.3-1 - 2.4.3 * Sat May 17 2008 Stu Tomlinson 2.4.2-1 - 2.4.2 * Tue May 13 2008 Stu Tomlinson 2.4.1-3 - Rebuild for new evolution-data-server - Clean up default prefs.xml - Enable nautilus integration plugin by default in prefs.xml (#242289)

References


[ 1 ] Bug #500488 - CVE-2009-1373 pidgin file transfer buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=500488 [ 2 ] Bug #500490 - CVE-2009-1374 pidgin DoS when decrypting qq packets https://bugzilla.redhat.com/show_bug.cgi?id=500490 [ 3 ] Bug #500491 - CVE-2009-1375 pidgin PurpleCircBuffer corruption https://bugzilla.redhat.com/show_bug.cgi?id=500491 [ 4 ] Bug #500493 - CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927 https://bugzilla.redhat.com/show_bug.cgi?id=500493

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pidgin
Product: Fedora 9
Version: 2.5.6
Release: 1.fc9
Summary: A Gtk+ based multiprotocol instant messaging client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here