Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

openSUSE 12.3: 2023:0710-1 Critical: Pidgin Security Vulnerability

opensuse
Calendar Grey March 21, 2013
Dist Opensuse Esm H88
A crucial security notice for Fedora points out significant vulnerabilities in Gnome with essential patches for version 34 users.
An update that fixes four vulnerabilities is now available

Description

Pidgin was updated to 2.10.7 to fix various security issues

and the bug that IRC did not work at all in 12.3.

Changes:

- Add pidgin-irc-sasl.patch: link irc module to SASL.

Allows the IRC module to be loaded (bnc#806975).

- Update to version 2.10.7 (bnc#804742):

+ Alien hatchery:

- No changes

+ General:

- The configure script will now exit with status 1 when

specifying invalid protocol plugins using the

--with-static-prpls and --with-dynamic-prpls

arguments. (pidgin.im#15316)

+ libpurple:

- Fix a crash when receiving UPnP responses with

abnormally long values. (CVE-2013-0274)

- Don't link directly to libgcrypt when building with

GnuTLS support. (pidgin.im#15329)

- Fix UPnP mappings on routers that return empty

elements in their response. (pidgin.im#15373)

- Tcl plugin uses saner, race-free plugin loading.

- Fix the Tcl signals-test plugin for

savedstatus-changed. (pidgin.im#15443)

+ Pidgin:

- Make Pidgin...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2013-231

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (i586 x86_64):

finch-2.10.7-4.4.1

finch-debuginfo-2.10.7-4.4.1

finch-devel-2.10.7-4.4.1

libpurple-2.10.7-4.4.1

libpurple-debuginfo-2.10.7-4.4.1

libpurple-devel-2.10.7-4.4.1

libpurple-meanwhile-2.10.7-4.4.1

libpurple-meanwhile-debuginfo-2.10.7-4.4.1

libpurple-tcl-2.10.7-4.4.1

libpurple-tcl-debuginfo-2.10.7-4.4.1

pidgin-2.10.7-4.4.1

pidgin-debuginfo-2.10.7-4.4.1

pidgin-debugsource-2.10.7-4.4.1

pidgin-devel-2.10.7-4.4.1

- openSUSE 12.3 (noarch):

libpurple-branding-upstream-2.10.7-4.4.1

libpurple-lang-2.10.7-4.4.1

References

https://www.suse.com/security/cve/CVE-2013-0271.html

https://www.suse.com/security/cve/CVE-2013-0272.html

https://www.suse.com/security/cve/CVE-2013-0273.html

https://www.suse.com/security/cve/CVE-2013-0274.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0511-1
Rating: important
Affected Products: openSUSE 12.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here