Synopsis:    Moderate: pidgin security update
Issue Date:  2011-10-13
CVE Numbers: CVE-2011-1091
             CVE-2011-3594


Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted SILC message. (CVE-2011-3594)

Multiple NULL pointer dereference flaws were found in the way the Pidgin
Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote
attacker could use these flaws to crash Pidgin via a specially-crafted
notification message. (CVE-2011-1091)

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.

SL4:
  i386
     finch-2.6.6-7.el4.i386.rpm
     finch-devel-2.6.6-7.el4.i386.rpm
     libpurple-2.6.6-7.el4.i386.rpm
     libpurple-devel-2.6.6-7.el4.i386.rpm
     libpurple-perl-2.6.6-7.el4.i386.rpm
     libpurple-tcl-2.6.6-7.el4.i386.rpm
     pidgin-2.6.6-7.el4.i386.rpm
     pidgin-debuginfo-2.6.6-7.el4.i386.rpm
     pidgin-devel-2.6.6-7.el4.i386.rpm
     pidgin-perl-2.6.6-7.el4.i386.rpm
  x86_64
     finch-2.6.6-7.el4.x86_64.rpm
     finch-devel-2.6.6-7.el4.x86_64.rpm
     libpurple-2.6.6-7.el4.x86_64.rpm
     libpurple-devel-2.6.6-7.el4.x86_64.rpm
     libpurple-perl-2.6.6-7.el4.x86_64.rpm
     libpurple-tcl-2.6.6-7.el4.x86_64.rpm
     pidgin-2.6.6-7.el4.x86_64.rpm
     pidgin-debuginfo-2.6.6-7.el4.x86_64.rpm
     pidgin-devel-2.6.6-7.el4.x86_64.rpm
     pidgin-perl-2.6.6-7.el4.x86_64.rpm
SL5:
  i386
     finch-2.6.6-5.el5_7.1.i386.rpm
     finch-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-2.6.6-5.el5_7.1.i386.rpm
     libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-perl-2.6.6-5.el5_7.1.i386.rpm
     libpurple-tcl-2.6.6-5.el5_7.1.i386.rpm
     pidgin-2.6.6-5.el5_7.1.i386.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
     pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
     pidgin-perl-2.6.6-5.el5_7.1.i386.rpm
  x86_64
     finch-2.6.6-5.el5_7.1.i386.rpm
     finch-2.6.6-5.el5_7.1.x86_64.rpm
     finch-devel-2.6.6-5.el5_7.1.i386.rpm
     finch-devel-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-2.6.6-5.el5_7.1.i386.rpm
     libpurple-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-devel-2.6.6-5.el5_7.1.i386.rpm
     libpurple-devel-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-perl-2.6.6-5.el5_7.1.x86_64.rpm
     libpurple-tcl-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-2.6.6-5.el5_7.1.i386.rpm
     pidgin-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.i386.rpm
     pidgin-debuginfo-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-devel-2.6.6-5.el5_7.1.i386.rpm
     pidgin-devel-2.6.6-5.el5_7.1.x86_64.rpm
     pidgin-perl-2.6.6-5.el5_7.1.x86_64.rpm

- Scientific Linux Development Team