SCIENTIFIC-LINUX-ERRATA Archives

October 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Fri, 14 Oct 2011 09:24:49 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (79 lines)
Synopsis:    Moderate: pidgin security update
Issue Date:  2011-10-13
CVE Numbers: CVE-2011-1091
             CVE-2011-3594


Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted SILC message. (CVE-2011-3594)

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.

SL4:
  i386
     finch-2.6.6-7.el4.i386.rpm
     finch-devel-2.6.6-7.el4.i386.rpm
     libpurple-2.6.6-7.el4.i386.rpm
     libpurple-devel-2.6.6-7.el4.i386.rpm
     libpurple-perl-2.6.6-7.el4.i386.rpm
     libpurple-tcl-2.6.6-7.el4.i386.rpm
     pidgin-2.6.6-7.el4.i386.rpm
     pidgin-debuginfo-2.6.6-7.el4.i386.rpm
     pidgin-devel-2.6.6-7.el4.i386.rpm
     pidgin-perl-2.6.6-7.el4.i386.rpm
  x86_64
     finch-2.6.6-7.el4.x86_64.rpm
     finch-devel-2.6.6-7.el4.x86_64.rpm
     libpurple-2.6.6-7.el4.x86_64.rpm
     libpurple-devel-2.6.6-7.el4.x86_64.rpm
     libpurple-perl-2.6.6-7.el4.x86_64.rpm
     libpurple-tcl-2.6.6-7.el4.x86_64.rpm
     pidgin-2.6.6-7.el4.x86_64.rpm
     pidgin-debuginfo-2.6.6-7.el4.x86_64.rpm
     pidgin-devel-2.6.6-7.el4.x86_64.rpm
     pidgin-perl-2.6.6-7.el4.x86_64.rpm
SL5:
  i386
     finch-2.6.6-5.el5_7.1.i386.rpm
     finch-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-2.6.6-5.el5_7.1.i386.rpm
     libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-perl-2.6.6-5.el5_7.1.i386.rpm
     libpurple-tcl-2.6.6-5.el5_7.1.i386.rpm
     pidgin-2.6.6-5.el5_7.1.i386.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
     pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
     pidgin-perl-2.6.6-5.el5_7.1.i386.rpm
  x86_64
     finch-2.6.6-5.el5_7.1.i386.rpm
     finch-2.6.6-5.el5_7.1.x86_64.rpm
     finch-devel-2.6.6-5.el5_7.1.i386.rpm
     finch-devel-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-2.6.6-5.el5_7.1.i386.rpm
     libpurple-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-devel-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-perl-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-tcl-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-2.6.6-5.el5_7.1.i386.rpm
     pidgin-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
     pidgin-devel-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-perl-2.6.6-5.el5_7.1.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2