Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Scientific Linux: Moderate Pidgin Update: 2011-10-13 DoS Risks

Scientific Large Esm H500
Moderate: pidgin security update
Date: Fri, 14 Oct 2011 09:24:49 -0500
Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: pidgin on SL4.x, SL5.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis: Moderate: pidgin security update
Issue Date: 2011-10-13
CVE Numbers: CVE-2011-1091
 CVE-2011-3594

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted SILC message. (CVE-2011-3594)

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.

SL4:
 i386
 finch-2.6.6-7.el4.i386.rpm
 finch-devel-2.6.6-7.el4.i386.rpm
 libpurple-2.6.6-7.el4.i386.rpm
 libpurple-devel-2.6.6-7.el4.i386.rpm
 libpurple-perl-2.6.6-7.el4.i386.rpm
 libpurple-tcl-2.6.6-7.el4.i386.rpm
 pidgin-2.6.6-7.el4.i386.rpm
 pidgin-debuginfo-2.6.6-7.el4.i386.rpm
 pidgin-devel-2.6.6-7.el4.i386.rpm
 pidgin-perl-2.6.6-7.el4.i386.rpm
 x86_64
 finch-2.6.6-7.el4.x86_64.rpm
 finch-devel-2.6.6-7.el4.x86_64.rpm
 libpurple-2.6.6-7.el4.x86_64.rpm
 libpurple-devel-2.6.6-7.el4.x86_64.rpm
 libpurple-perl-2.6.6-7.el4.x86_64.rpm
 libpurple-tcl-2.6.6-7.el4.x86_64.rpm
 pidgin-2.6.6-7.el4.x86_64.rpm
 pidgin-debuginfo-2.6.6-7.el4.x86_64.rpm
 pidgin-devel-2.6.6-7.el4.x86_64.rpm
 pidgin-perl-2.6.6-7.el4.x86_64.rpm
SL5:
 i386
 finch-2.6.6-5.el5_7.1.i386.rpm
 finch-devel-2.6.6-5.el5_7.1.i386.rpm
 libpurple-2.6.6-5.el5_7.1.i386.rpm
 libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
 libpurple-perl-2.6.6-5.el5_7.1.i386.rpm
 libpurple-tcl-2.6.6-5.el5_7.1.i386.rpm
 pidgin-2.6.6-5.el5_7.1.i386.rpm
 pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
 pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
 pidgin-perl-2.6.6-5.el5_7.1.i386.rpm
 x86_64
 finch-2.6.6-5.el5_7.1.i386.rpm
 finch-2.6.6-5.el5_7.1.x86_64.rpm
 finch-devel-2.6.6-5.el5_7.1.i386.rpm
 finch-devel-2.6.6-5.el5_7.1.x86_64.rpm
 libpurple-2.6.6-5.el5_7.1.i386.rpm
 libpurple-2.6.6-5.el5_7.1.x86_64.rpm
 libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
 libpurple-devel-2.6.6-5.el5_7.1.x86_64.rpm
 libpurple-perl-2.6.6-5.el5_7.1.x86_64.rpm
 libpurple-tcl-2.6.6-5.el5_7.1.x86_64.rpm
 pidgin-2.6.6-5.el5_7.1.i386.rpm
 pidgin-2.6.6-5.el5_7.1.x86_64.rpm
 pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
 pidgin-debuginfo-2.6.6-5.el5_7.1.x86_64.rpm
 pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
 pidgin-devel-2.6.6-5.el5_7.1.x86_64.rpm
 pidgin-perl-2.6.6-5.el5_7.1.x86_64.rpm

- Scientific Linux Development Team
Your message here