Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Pidgin.
Software Description:
- pidgin: graphical multi-protocol instant messaging client for X
Details:
Evgeny Boger discovered that Pidgin incorrectly handled buddy list messages in
the AIM and ICQ protocol handlers. A remote attacker could send a specially
crafted message and cause Pidgin to crash, leading to a denial of service. This
issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10. (CVE-2011-4601)
Thijs Alkemade discovered that Pidgin incorrectly handled malformed voice and
video chat requests in the XMPP protocol handler. A remote attacker could send
a specially crafted message and cause Pidgin to crash, leading to a denial of
service. This issue only affected Ubuntu 10.04 LTS, 11.04 and 11.10.
(CVE-2011-4602)
Diego Bauche Madero discovered that Pidgin incorrectly handled UTF-8
sequences in the SILC protocol handler. A remote attacker could send a
specially crafted message and cause Pidgin to crash, leading ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: finch 1:2.10.3-0ubuntu1.1 libpurple0 1:2.10.3-0ubuntu1.1 pidgin 1:2.10.3-0ubuntu1.1 Ubuntu 11.10: finch 1:2.10.0-0ubuntu2.1 libpurple0 1:2.10.0-0ubuntu2.1 pidgin 1:2.10.0-0ubuntu2.1 Ubuntu 11.04: finch 1:2.7.11-1ubuntu2.2 libpurple0 1:2.7.11-1ubuntu2.2 pidgin 1:2.7.11-1ubuntu2.2 Ubuntu 10.04 LTS: finch 1:2.6.6-1ubuntu4.5 libpurple0 1:2.6.6-1ubuntu4.5 pidgin 1:2.6.6-1ubuntu4.5 After a standard system update you need to restart Pidgin to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1500-1
CVE-2011-4601, CVE-2011-4602, CVE-2011-4603, CVE-2011-4922,
CVE-2011-4939, CVE-2012-1178, CVE-2012-2214, CVE-2012-2318,
CVE-2012-3374
Get the latest Linux and open source security news straight to your inbox.