2.6.1 fixes an issue where pidgin can crash if you are sent a certain type of URL over Yahoo.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8826 2009-08-22 00:01:44 -------------------------------------------------------------------------------- Name : pidgin Product : Fedora 10 Version : 2.6.1 Release : 1.fc10 URL : http://pidgin.im/ Summary : A Gtk+ based multiprotocol instant messaging client Description : Pidgin allows you to talk to anyone using a variety of messaging protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu, ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Pidgin supports many common features of other clients, as well as many unique features, such as perl scripting, TCL scripting and C plugins. Pidgin is not affiliated with or endorsed by America Online, Inc., Microsoft Corporation, Yahoo! Inc., or ICQ Inc. -------------------------------------------------------------------------------- Update Information: 2.6.1 fixes an issue where pidgin can crash if you are sent a certain type of URL over Yahoo. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 19 2009 Warren Togami 2.6.1-1 - 2.6.1: Fix a crash when some users send you a link in a Yahoo IM * Tue Aug 18 2009 Warren Togami 2.6.0-1 - CVE-2009-2694 - Voice and Video support via farsight2 (Fedora 11+) - Numerous other bug fixes * Thu Aug 6 2009 Warren Togami 2.6.0-0.11.20090812 - new snapshot at the request of maiku * Thu Aug 6 2009 Warren Togami 2.6.0-0.10.20090806 - new snapshot - theoretically better sound quality in voice chat * Tue Aug 4 2009 Warren Togami 2.6.0-0.9.20090804 - new snapshot * Mon Jul 27 2009 Warren Togami 2.6.0-0.8.20090727 - new snapshot * Mon Jul 27 2009 Stu Tomlinson 2.6.0-0.6.20090721 - Prevent main libpurple & pidgin packages depending on perl (#513902) * Sun Jul 26 2009 Fedora Release Engineering - 2.6.0-0.5.20090721 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Wed Jul 22 2009 Warren Togami 2.6.0-0.4.20090721 - rebuild * Tue Jul 21 2009 Warren Togami 2.6.0-0.3.20090721 - prevent crash with no camera when closing vv window * Tue Jul 21 2009 Warren Togami 2.6.0-0.1.20090721 - 2.6.0 snapshot with voice and video support via farsight2 * Sat Jul 11 2009 Stu Tomlison 2.5.8-2 - Backport patch from upstream to enable NSS to recognize root CA certificates that use MD2 & MD4 algorithms in their signature, as used by some MSN and XMPP servers* Sun Jun 28 2009 Warren Togami 2.5.8-1 - 2.5.8 with several important bug fixes * Mon Jun 22 2009 Warren Togami 2.5.7-2 - glib2 compat with RHEL-4 * Sat Jun 20 2009 Warren Togami 2.5.7-1 - 2.5.7 with Yahoo Protocol 16 support * Wed May 20 2009 Stu Tomlinson 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami 2.5.5-3 - F12+ removed krb4 * Tue Mar 3 2009 Stu Tomlinson 2.5.5-1 - 2.5.5 * Thu Feb 26 2009 Fedora Release Engineering - 2.5.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Tue Jan 27 2009 Warren Togami 2.5.4-2 - one_time_password plugin - Eliminate RPATH * Mon Jan 12 2009 Stu Tomlinson 2.5.4-1 - 2.5.4 * Fri Dec 26 2008 Warren Togami 2.5.3-1 - 2.5.3 * Sat Nov 22 2008 Warren Togami 2.5.2-6 - Automatically detect booleans to enable build features from dist tag - Unify RHEL4 and RHEL5 spec with Fedora to make both easier to maintain * Fri Nov 21 2008 Warren Togami 2.5.2-2 - Upstream backports: 100: sametime-redirect-null crash 101: NetworkManager-improvement 102: no-password-in-dialog-if-not-remembering 103: temporarily-remember-password-during-auto-reconnect 104: smilie-theme-change-crash 105: url_fetch_connect_cb-double-free crash 106: GtkIMHtmlSmileys-remove-crash 107:remove-dialog-from-open-dialog-list -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
pidgin upgrade to 2.6.0 for the CVE-2009-2694, insufficient input validation in msn_slplink_process_msg(). 2.6.0 has Voice and Video support via farsight2 (Fedora 11+ only) and numerous other bug fixes. farsight2, libnice and gupnp- igd are version upgrades to make voice and video actually work on Fedora 11.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8804 2009-08-20 20:33:46 -------------------------------------------------------------------------------- Name : pidgin Product : Fedora 11 Version : 2.6.0 Release : 1.fc11 URL : http://pidgin.im/ Summary : A Gtk+ based multiprotocol instant messaging client Description : Pidgin allows you to talk to anyone using a variety of messaging protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu, ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Pidgin supports many common features of other clients, as well as many unique features, such as perl scripting, TCL scripting and C plugins. Pidgin is not affiliated with or endorsed by America Online, Inc., Microsoft Corporation, Yahoo! Inc., or ICQ Inc. -------------------------------------------------------------------------------- Update Information: pidgin upgrade to 2.6.0 for the CVE-2009-2694, insufficient input validation in msn_slplink_process_msg(). 2.6.0 has Voice and Video support via farsight2 (Fedora 11+ only) and numerous other bug fixes. farsight2, libnice and gupnp- igd are version upgrades to make voice and video actually work on Fedora 11. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 18 2009 Warren Togami 2.6.0-1 - CVE-2009-2694 - Voice and Video support via farsight2 (Fedora 11+) - Numerous other bug fixes * Thu Aug 6 2009 Warren Togami 2.6.0-0.11.20090812 -new snapshot at the request of maiku * Thu Aug 6 2009 Warren Togami 2.6.0-0.10.20090806 - new snapshot - theoretically better sound quality in voice chat * Tue Aug 4 2009 Warren Togami 2.6.0-0.9.20090804 - new snapshot * Mon Jul 27 2009 Warren Togami 2.6.0-0.8.20090727 - new snapshot * Mon Jul 27 2009 Stu Tomlinson 2.6.0-0.6.20090721 - Prevent main libpurple & pidgin packages depending on perl (#513902) * Sun Jul 26 2009 Fedora Release Engineering - 2.6.0-0.5.20090721 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Wed Jul 22 2009 Warren Togami 2.6.0-0.4.20090721 - rebuild * Tue Jul 21 2009 Warren Togami 2.6.0-0.3.20090721 - prevent crash with no camera when closing vv window * Tue Jul 21 2009 Warren Togami 2.6.0-0.1.20090721 - 2.6.0 snapshot with voice and video support via farsight2 * Sat Jul 11 2009 Stu Tomlison 2.5.8-2 - Backport patch from upstream to enable NSS to recognize root CA certificates that use MD2 & MD4 algorithms in their signature, as used by some MSN and XMPP servers* Sun Jun 28 2009 Warren Togami 2.5.8-1 - 2.5.8 with several important bug fixes * Mon Jun 22 2009 Warren Togami 2.5.7-2 - glib2 compat with RHEL-4 * Sat Jun 20 2009 Warren Togami 2.5.7-1 - 2.5.7 with Yahoo Protocol 16 support * Wed May 20 2009 Stu Tomlinson 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami 2.5.5-3 - F12+ removed krb4 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist
It was discovered that gaim, an multi-protocol instant messaging client, was vulnerable to several integer overflows in its MSN protocol handlers. These could allow a remote attacker to execute arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1610-1
Gaim allows you to talk to anyone using a variety of messaging protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!, MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-525 2004-12-06 ---------------------------------------------------------------------Product : Fedora Core 2 Name : gaim Version : 1.1.0 Release : 0.FC2 Summary : A Gtk+ based multiprotocol instant messaging client Description : Gaim allows you to talk to anyone using a variety of messaging protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!, MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Gaim supports many common features of other clients, as well as many unique features, such as perl scripting and C plugins. Gaim is NOT affiliated with or endorsed by America Online, Inc., Microsoft Corporation, or Yahoo! Inc. or other messaging service providers. ---------------------------------------------------------------------* Thu Dec 02 2004 Warren Togami 1.1.0-0.FC2 - FC2 update * Thu Dec 02 2004 Warren Togami 1.1.0-1 - upgrade 1.1.0 (mostly bugfixes) - fix PIE patch * Fri Nov 12 2004 Warren Togami 1.0.3-1 - 1.0.3 another bugfix release ---------------------------------------------------------------------This update can be downloaded from: eece1efc788c240774d36f45f1cc8642 SRPMS/gaim-1.1.0-0.FC2.src.rpm e7454ac9cbd11a199df9ca9363f63fb6 x86_64/gaim-1.1.0-0.FC2.x86_64.rpm ae7d3ec56c450b9e54c06400c9f0a507 x86_64/debug/gaim-debuginfo-1.1.0-0.FC2.x86_64.rpm 030c4ccfd49913e74d819f42c6b712bb i386/gaim-1.1.0-0.FC2.i386.rpm cc531ad9cca28c97a7e5532479ca584d i386/debug/gaim-debuginfo-1.1.0-0.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
FC2 Update. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-354 2004-10-28 --------------------------------------------------------------------- Product : Fedora Core 2 Name : gaim Version : 1.0.2 Release : 0.FC2 Summary : A Gtk+ based multiprotocol instant messaging client Description : Gaim allows you to talk to anyone using a variety of messaging protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!, MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Gaim supports many common features of other clients, as well as many unique features, such as perl scripting and C plugins. Gaim is NOT affiliated with or endorsed by America Online, Inc., Microsoft Corporation, or Yahoo! Inc. or other messaging service providers. --------------------------------------------------------------------- * Thu Oct 21 2004 Warren Togami 1.0.2-0.FC2 - FC2 Update * Tue Oct 19 2004 Warren Togami 1.0.2-1 - 1.0.2 fixes many crashes, endian and other issues * Tue Oct 19 2004 Warren Togami 1.0.1-3 - nosnilmot: zephyr krb build was broken by thinko * Wed Oct 13 2004 Warren Togami 1.0.1-2 - CAN-2004-0891 * Thu Oct 07 2004 Warren Togami 1.0.1-1 - update to 1.0.1 - disable naive GNOME session check - switch to gnutls default (FC3+) --------------------------------------------------------------------- This update can be downloaded from: 293c4826574e1a0d5b9e2e296a406dd9 SRPMS/gaim-1.0.2-0.FC2.src.rpm f7ad9e550e33eefe0ef88361001f8514 x86_64/gaim-1.0.2-0.FC2.x86_64.rpm fef45019036eacb644ceba33eae662dd x86_64/debug/gaim-debuginfo-1.0.2-0.FC2.x86_64.rpm 07cd19bb8f237e34fef9af2a67270c0f i386/gaim-1.0.2-0.FC2.i386.rpm be1bd069ebca2fa6d6f4b56786d383a4 i386/debug/gaim-debuginfo-1.0.2-0.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
1.0.3 another bugfix release. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-432 2004-11-16 --------------------------------------------------------------------- Product : Fedora Core 3 Name : gaim Version : 1.0.3 Release : 0.FC3 Summary : A Gtk+ based multiprotocol instant messaging client Description : Gaim allows you to talk to anyone using a variety of messaging protocols, including AIM (Oscar and TOC), ICQ, IRC, Yahoo!, MSN Messenger, Jabber, Gadu-Gadu, Napster, and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Gaim supports many common features of other clients, as well as many unique features, such as perl scripting and C plugins. Gaim is NOT affiliated with or endorsed by America Online, Inc., Microsoft Corporation, or Yahoo! Inc. or other messaging service providers. --------------------------------------------------------------------- * Fri Nov 12 2004 Warren Togami 1.0.3-0.FC3 - 1.0.3 another bugfix release --------------------------------------------------------------------- This update can be downloaded from: 87f1981114c6d88e4b4ac10e34d8a4f3 SRPMS/gaim-1.0.3-0.FC3.src.rpm 8076180c823d4dcc11d6619f83882a1d x86_64/gaim-1.0.3-0.FC3.x86_64.rpm c357cb1c75fc6c6df29c51c4950298a4 x86_64/debug/gaim-debuginfo-1.0.3-0.FC3.x86_64.rpm 7ffab75d618c3712b6ea331f1fb34108 i386/gaim-1.0.3-0.FC3.i386.rpm 17f00e2b15df2fdfc8d66052af104ecc i386/debug/gaim-debuginfo-1.0.3-0.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.