First published: Thu Jan 14 2010(Updated: )
Pidgin is an instant messaging program which can log in to multiple<br>accounts on multiple instant messaging networks simultaneously.<br>A directory traversal flaw was discovered in Pidgin's MSN protocol<br>implementation. A remote attacker could send a specially-crafted emoticon<br>image download request that would cause Pidgin to disclose an arbitrary<br>file readable to the user running Pidgin. (CVE-2010-0013)<br>These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin release<br>notes for a full list of changes: <a href="http://developer.pidgin.im/wiki/ChangeLog" target="_blank">http://developer.pidgin.im/wiki/ChangeLog</a> All Pidgin users should upgrade to these updated packages, which correct<br>this issue. Pidgin must be restarted for this update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pidgin | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/finch | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/finch | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/finch-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/finch-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-perl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-tcl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin-devel | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin-perl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-perl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/libpurple-tcl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin-perl | <2.6.5-1.el5 | 2.6.5-1.el5 |
redhat/pidgin | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/finch | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/finch-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-perl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-tcl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/pidgin | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/pidgin-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/pidgin-perl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/finch | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/finch-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-perl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/libpurple-tcl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/pidgin-devel | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
redhat/pidgin-perl | <2.6.5-1.el4.1 | 2.6.5-1.el4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.