Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SciLinux: Moderate Pidgin Security Update on SL6.x for Remote Attack

Scientific Large Esm H500
Moderate: pidgin security update
Date: Thu, 15 Dec 2011 15:25:06 -0600
Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: pidgin on SL6.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis: Moderate: pidgin security update
Issue Date: 2011-12-14
CVE Numbers: CVE-2011-4602
 CVE-2011-4601

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the AOL Open System for
Communication in Realtime (OSCAR) protocol plug-in in Pidgin, used by the
AOL ICQ and AIM instant messaging systems, escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted OSCAR message. (CVE-2011-4601)

Multiple NULL pointer dereference flaws were found in the Jingle extension
of the Extensible Messaging and Presence Protocol (XMPP) protocol plug-in
in Pidgin. A remote attacker could use these flaws to crash Pidgin via a
specially-crafted Jingle multimedia message. (CVE-2011-4602)

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.

SL6:
 i386
 finch-2.7.9-3.el6.2.i686.rpm
 finch-devel-2.7.9-3.el6.2.i686.rpm
 libpurple-2.7.9-3.el6.2.i686.rpm
 libpurple-devel-2.7.9-3.el6.2.i686.rpm
 libpurple-perl-2.7.9-3.el6.2.i686.rpm
 libpurple-tcl-2.7.9-3.el6.2.i686.rpm
 pidgin-2.7.9-3.el6.2.i686.rpm
 pidgin-debuginfo-2.7.9-3.el6.2.i686.rpm
 pidgin-devel-2.7.9-3.el6.2.i686.rpm
 pidgin-docs-2.7.9-3.el6.2.i686.rpm
 pidgin-perl-2.7.9-3.el6.2.i686.rpm
 x86_64
 finch-2.7.9-3.el6.2.i686.rpm
 finch-2.7.9-3.el6.2.x86_64.rpm
 finch-devel-2.7.9-3.el6.2.i686.rpm
 finch-devel-2.7.9-3.el6.2.x86_64.rpm
 libpurple-2.7.9-3.el6.2.i686.rpm
 libpurple-2.7.9-3.el6.2.x86_64.rpm
 libpurple-devel-2.7.9-3.el6.2.i686.rpm
 libpurple-devel-2.7.9-3.el6.2.x86_64.rpm
 libpurple-perl-2.7.9-3.el6.2.x86_64.rpm
 libpurple-tcl-2.7.9-3.el6.2.x86_64.rpm
 pidgin-2.7.9-3.el6.2.x86_64.rpm
 pidgin-debuginfo-2.7.9-3.el6.2.i686.rpm
 pidgin-debuginfo-2.7.9-3.el6.2.x86_64.rpm
 pidgin-devel-2.7.9-3.el6.2.i686.rpm
 pidgin-devel-2.7.9-3.el6.2.x86_64.rpm
 pidgin-docs-2.7.9-3.el6.2.x86_64.rpm
 pidgin-perl-2.7.9-3.el6.2.x86_64.rpm

- Scientific Linux Development Team

Related News

Your message here