pidgin 1.2.11 backport required

Bug #1465052 reported by StoatWblr
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
pidgin (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

bug #1402424 (a gaping security/information leak hole in Vivid's Pidgin) has been marked as closed, despite the fact that an updated version has not been released for Vivid, per the original bug report.

https://bugs.launchpad.net/ubuntu/+source/pidgin/+bug/1402424

Apparently releasing a security fixed version for a non-released distribution (wily) is "good enough"

This needs backporting from Wily asap.

These are the unfixed, publically disclosed vulnerabilties in the distributed version:

https://pidgin.im/news/security/

 CVE Name Date Fixed In
Potential information leak from XMPP CVE-2014-3698 2014-10-22 2.10.10
Malicious smiley themes could alter arbitrary files CVE-2014-3697 2014-10-22 2.10.10
Remote crash parsing malformed Groupwise message CVE-2014-3696 2014-10-22 2.10.10
Remote crash parsing malformed MXit emoticon CVE-2014-3695 2014-10-22 2.10.10
Insufficient SSL certificate validation CVE-2014-3694 2014-10-22 2.10.10

StoatWblr (stoatwblr)
information type: Private Security → Public
Revision history for this message
Micah Gersten (micahg) wrote :
affects: vivid-backports → pidgin (Ubuntu)
Changed in pidgin (Ubuntu):
status: New → Invalid
information type: Public → Public Security
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.