RHSA-2010:0788: Moderate: pidgin security update
Pidgin is an instant messaging program which can log in to multipleaccounts on multiple instant messaging networks simultaneously.Multiple NULL pointer dereference flaws were found in the way Pidginhandled Base64 decoding. A remote attacker could use these flaws to crashPidgin if the target Pidgin user was using the Yahoo! Messenger Protocol,MSN, MySpace, or Extensible Messaging and Presence Protocol (XMPP) protocolplug-ins, or using the Microsoft NT LAN Manager (NTLM) protocol forauthentication. (CVE-2010-3711)A NULL pointer dereference flaw was found in the way the Pidgin MSNprotocol plug-in processed custom emoticon messages. A remote attackercould use this flaw to crash Pidgin by sending specially-crafted emoticonmessages during mutual communication. (CVE-2010-1624)Red Hat would like to thank the Pidgin project for reporting these issues.Upstream acknowledges Daniel Atallah as the original reporter ofCVE-2010-3711, and Pierre Nogues of Meta Security as the original reporterof CVE-2010-1624.All Pidgin users should upgrade to these updated packages, which containbackported patches to resolve these issues. Pidgin must be restarted forthis update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0788?
RHSA-2010:0788 has been rated as moderate severity due to multiple NULL pointer dereference flaws in Pidgin.
How do I fix RHSA-2010:0788?
To resolve RHSA-2010:0788, install the updated version 2.6.6-5.el5_5 of Pidgin or related packages provided by Red Hat.
Which software is affected by RHSA-2010:0788?
RHSA-2010:0788 affects Pidgin, Finch, and associated libraries such as libpurple and their development files.
Can RHSA-2010:0788 lead to a denial of service?
Yes, the vulnerabilities in RHSA-2010:0788 can be exploited by a remote attacker to cause a denial of service by crashing the application.
Is there a specific version I need to update to for RHSA-2010:0788?
You need to update to version 2.6.6-5.el5_5 or later of the affected packages to mitigate the risks associated with RHSA-2010:0788.