RHSA-2010:0044: Important: pidgin security update
Pidgin is an instant messaging program which can log in to multipleaccounts on multiple instant messaging networks simultaneously.A directory traversal flaw was discovered in Pidgin's MSN protocolimplementation. A remote attacker could send a specially-crafted emoticonimage download request that would cause Pidgin to disclose an arbitraryfile readable to the user running Pidgin. (CVE-2010-0013)These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin releasenotes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog All Pidgin users should upgrade to these updated packages, which correctthis issue. Pidgin must be restarted for this update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0044?
The severity of RHSA-2010:0044 is classified as important.
How do I fix RHSA-2010:0044?
To fix RHSA-2010:0044, upgrade the affected packages to the specified version 2.6.5-1.el5 or later.
What software is affected by RHSA-2010:0044?
RHSA-2010:0044 affects Pidgin, Finch, and related libraries including libpurple.
Can RHSA-2010:0044 lead to remote code execution?
Yes, the directory traversal flaw in RHSA-2010:0044 can potentially be exploited by remote attackers.
Is RHSA-2010:0044 applicable to all users of Pidgin?
RHSA-2010:0044 is applicable to users of Pidgin versions earlier than 2.6.5-1.el5.