Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE 11.4 Security Update: 2013:0407-1 Important Pidgin Risk

opensuse
Calendar Grey March 7, 2013
Dist Opensuse Esm H88
Important update for openSUSE regarding pidgin fixes several vulnerabilities. Ensure you adhere to the proper steps for a secure setup.
An update that fixes three vulnerabilities is now available

Description

pidgin was updated to fix security issues:

- Fix a crash when receiving UPnP responses with abnormally

long values. (CVE-2013-0274)

- Fix a crash in Sametime when a malicious server sends us

an abnormally long user ID. (CVE-2013-0273)

- Fix a bug where the MXit server or a man-in-the-middle

could potentially send specially crafted data that could

overflow a buffer and lead to a crash or remote code

execution.(CVE-2013-0272)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2013-35

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

finch-2.7.10-4.53.1

finch-debuginfo-2.7.10-4.53.1

finch-devel-2.7.10-4.53.1

libpurple-2.7.10-4.53.1

libpurple-debuginfo-2.7.10-4.53.1

libpurple-devel-2.7.10-4.53.1

libpurple-meanwhile-2.7.10-4.53.1

libpurple-meanwhile-debuginfo-2.7.10-4.53.1

libpurple-tcl-2.7.10-4.53.1

libpurple-tcl-debuginfo-2.7.10-4.53.1

pidgin-2.7.10-4.53.1

pidgin-debuginfo-2.7.10-4.53.1

pidgin-debugsource-2.7.10-4.53.1

pidgin-devel-2.7.10-4.53.1

pidgin-evolution-2.7.10-4.53.1

pidgin-evolution-debuginfo-2.7.10-4.53.1

- openSUSE 11.4 (noarch):

libpurple-lang-2.7.10-4.53.1

References

https://www.suse.com/security/cve/CVE-2013-0272.html

https://www.suse.com/security/cve/CVE-2013-0273.html

https://www.suse.com/security/cve/CVE-2013-0274.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0407-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here