Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Slackware 13.37: 2012-195-02 Critical: Pidgin Buffer Overflow Threat

slackware
Calendar Grey July 14, 2012
Scroller Slackware
Recent updates of pidgin for Slackware address crucial security vulnerabilities, notably a buffer overflow risk associated with MXit.
New pidgin packages are available for Slackware 12.2, 13.0, 13.1, 13.37, and -current to fix security issues

Summary

Here are the details from the Slackware 13.37 ChangeLog: patches/packages/pidgin-2.10.6-i486-1_slack13.37.txz: Upgraded. Fixes a security issue for users of MXit: Incorrect handing of inline images in incoming instant messages can cause a buffer overflow and in some cases can be exploited to execute arbitrary code. For more information, see: https://www.cve.org/CVERecord?id=CVE-2012-3374 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 12.2:
Updated package for Slackware 13.0:
Updated package for Slackware x86_64 13.0:
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 12.2 package: 995b3debf7bddb5fe74e6190d334ed46 pidgin-2.10.6-i486-1_slack12.2.tgz
Slackware 13.0 package: 9c142e63563a362ee29485b59f03c0e0 pidgin-2.10.6-i486-1_slack13.0.txz
Slackware x86_64 13.0 package: bdc195e52c60a47f8277cd3247f9de76 pidgin-2.10.6-x86_64-1_slack13.0.txz
Slackware 13.1 package: d001dbb823b5aa4b47b784529ddba7ee pidgin-2.10.6-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: ab4ef5ec851ebede8e355db3f4457f8d pidgin-2.10.6-x86_64-1_slack13.1.txz
Slackware 13.37 package: a9faf063cd155473628182a26aaf856e pidgin-2.10.6-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: e64729809335bbb2d875f7a2a369e03f pidgin-2.10.6-x86_64-1_slack13.37.txz
Slackware -current package: e26f06db9dc0e771a0add32685e9ab5b xap/pidgin-2.10.6-i486-1.txz
Slackware x86_64 -current package: fad6b8acf8f8489e48ff1b85b3bd3c0d xap/pidgin-2.10.6-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg pidgin-2.10.6-i486-1_slack13.37.txz