Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
New pidgin packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] pidgin (SSA:2022-120-01) New pidgin packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/pidgin-2.14.9-i586-1_slack15.0.txz: Upgraded. Mitigate the potential for a man in the middle attack via DNS spoofing by removing the code that supported the _xmppconnect DNS TXT record. For more information, see: https://www.pidgin.im/about/security/advisories/cve-2022-26491/ https://www.cve.org/CVERecord?id=CVE-2022-26491 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/pidgin-2.12.0-i486-2_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/pidgin-2.12.0-x86_64-2_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/pidgin-2.12.0-i486-2_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/pidgin-2.12.0-x86_64-2_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/pidgin-2.12.0-i586-2_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/pidgin-2.12.0-x86_64-2_slack14.2.txz Updated package for Slackware15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: c59bd678d1b199c036c8bfb75ca399c8 pidgin-2.12.0-i486-2_slack14.0.txz Slackware x86_64 14.0 package: 887fb4057696463926ad58474285f07f pidgin-2.12.0-x86_64-2_slack14.0.txz Slackware 14.1 package: e9cb93c85f98bfa880ec67c54af6ed6c pidgin-2.12.0-i486-2_slack14.1.txz Slackware x86_64 14.1 package: 86adbb2303e88642f1bd1b5707a7ddb8 pidgin-2.12.0-x86_64-2_slack14.1.txz Slackware 14.2 package: 96c6521a1c4a6a81c0d5ddd72022830d pidgin-2.12.0-i586-2_slack14.2.txz Slackware x86_64 14.2 package: 1b62360e3f9eda72af5c7f3991284ebf pidgin-2.12.0-x86_64-2_slack14.2.txz Slackware 15.0 package: ed238ac913f686097290072f2a01754d pidgin-2.14.9-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 63d4388542216a12f3a90614484295fb pidgin-2.14.9-x86_64-1_slack15.0.txz Slackware -current package: 769364f2537c93b74ea039228521d8a6 xap/pidgin-2.14.9-i586-1.txz Slackware x86_64 -current package: ec5431b3a2068a05bd6cbd0426e816a0 xap/pidgin-2.14.9-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg pidgin-2.14.9-i586-1_slack15.0.txz +-----+ . Fresh updates for the Pidgin application have been launched in Slackware, targeting a serious security vulnerability that allows for DNS spoofing attacks.. pidgin security fix, slackware update, ensure security, DNS attack mitigation. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for pidgin, finch and libpurple ______________________________________________________________________________ Announcement ID: SUSE-SU-2012:0890-1 Rating: important References: #770304 Cross-References: CVE-2012-3374 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Desktop 10 SP4 SLE SDK 10 SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update of pidgin fixes a stack-based buffer overflow in the MXit protocol which could have potentially been exploited by remote attackers to execute arbitrary code in the context of the user running pidgin (CVE-2012-3374). Security Issue reference: * CVE-2012-3374 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp1-finch-6534 - SUSE Linux Enterprise Software Development Kit 11 SP1: zypper in -t patch sdksp1-finch-6534 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp1-finch-6534 - SUSE Linux Enterprise Desktop 11 SP1: zypper in -t patch sledsp1-finch-6534 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64): finch-2.6.6-0.17.1 finch-devel-2.6.6-0.17.1 libpurple-2.6.6-0.17.1 libpurple-devel-2.6.6-0.17.1 libpurple-lang-2.6.6-0.17.1 pidgin-2.6.6-0.17.1 pidgin-devel-2.6.6-0.17.1 - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 ia64 ppc64 s390x x86_64): finch-2.6.6-0.17.1 finch-devel-2.6.6-0.17.1 libpurple-2.6.6-0.17.1 libpurple-devel-2.6.6-0.17.1 libpurple-lang-2.6.6-0.17.1 pidgin-2.6.6-0.17.1 pidgin-devel-2.6.6-0.17.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64): finch-2.6.6-0.17.1 libpurple-2.6.6-0.17.1 libpurple-lang-2.6.6-0.17.1 libpurple-meanwhile-2.6.6-0.17.1 libpurple-tcl-2.6.6-0.17.1 pidgin-2.6.6-0.17.1 - SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64): finch-2.6.6-0.17.1 libpurple-2.6.6-0.17.1 libpurple-lang-2.6.6-0.17.1 libpurple-meanwhile-2.6.6-0.17.1 libpurple-tcl-2.6.6-0.17.1 pidgin-2.6.6-0.17.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64): finch-2.6.6-0.18.1 libpurple-2.6.6-0.18.1 pidgin-2.6.6-0.18.1 - SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64): finch-2.6.6-0.18.1 finch-devel-2.6.6-0.18.1 libpurple-2.6.6-0.18.1 libpurple-devel-2.6.6-0.18.1 pidgin-2.6.6-0.18.1 pidgin-devel-2.6.6-0.18.1 References: https://www.suse.com/security/cve/CVE-2012-3374.html . SUSE Security Notification: Critical update released for pidgin, finch, and libpurple resolving severe buffer overflow vulnerability.. SUSE Linux, pidgin security, finch update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.