SCIENTIFIC-LINUX-ERRATA Archives

December 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 15 Dec 2011 15:25:06 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (58 lines)
Synopsis:    Moderate: pidgin security update
Issue Date:  2011-12-14
CVE Numbers: CVE-2011-4602
             CVE-2011-4601


Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the AOL Open System for
Communication in Realtime (OSCAR) protocol plug-in in Pidgin, used by the
AOL ICQ and AIM instant messaging systems, escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted OSCAR message. (CVE-2011-4601)

Multiple NULL pointer dereference flaws were found in the Jingle extension
of the Extensible Messaging and Presence Protocol (XMPP) protocol plug-in
in Pidgin. A remote attacker could use these flaws to crash Pidgin via a
specially-crafted Jingle multimedia message. (CVE-2011-4602)

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.

SL6:
  i386
     finch-2.7.9-3.el6.2.i686.rpm
     finch-devel-2.7.9-3.el6.2.i686.rpm
     libpurple-2.7.9-3.el6.2.i686.rpm
     libpurple-devel-2.7.9-3.el6.2.i686.rpm
     libpurple-perl-2.7.9-3.el6.2.i686.rpm
     libpurple-tcl-2.7.9-3.el6.2.i686.rpm
     pidgin-2.7.9-3.el6.2.i686.rpm
     pidgin-debuginfo-2.7.9-3.el6.2.i686.rpm
     pidgin-devel-2.7.9-3.el6.2.i686.rpm
     pidgin-docs-2.7.9-3.el6.2.i686.rpm
     pidgin-perl-2.7.9-3.el6.2.i686.rpm
  x86_64
     finch-2.7.9-3.el6.2.i686.rpm
     finch-2.7.9-3.el6.2.x86_64.rpm
     finch-devel-2.7.9-3.el6.2.i686.rpm
     finch-devel-2.7.9-3.el6.2.x86_64.rpm
     libpurple-2.7.9-3.el6.2.i686.rpm
     libpurple-2.7.9-3.el6.2.x86_64.rpm
     libpurple-devel-2.7.9-3.el6.2.i686.rpm
     libpurple-devel-2.7.9-3.el6.2.x86_64.rpm
     libpurple-perl-2.7.9-3.el6.2.x86_64.rpm
     libpurple-tcl-2.7.9-3.el6.2.x86_64.rpm
     pidgin-2.7.9-3.el6.2.x86_64.rpm
     pidgin-debuginfo-2.7.9-3.el6.2.i686.rpm
     pidgin-debuginfo-2.7.9-3.el6.2.x86_64.rpm
     pidgin-devel-2.7.9-3.el6.2.i686.rpm
     pidgin-devel-2.7.9-3.el6.2.x86_64.rpm
     pidgin-docs-2.7.9-3.el6.2.x86_64.rpm
     pidgin-perl-2.7.9-3.el6.2.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2