Please backport pidgin 2.5.2-0ubuntu1.4 to hardy

Bug #478258 reported by Philip Wyett
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Hardy Backports
Won't Fix
Undecided
Unassigned

Bug Description

Hardy backports already contains 2.5.2-0ubuntu1.2 from intrepid. Can we update to the intrepid update 2.5.2-0ubuntu1.4 version that fixes a number of CVE issues.

pidgin (1:2.5.2-0ubuntu1.4) intrepid-security; urgency=low

  * SECURITY UPDATE: arbitrary code execution via crafted MSNSLP packet
    (LP: #415863)
    - debian/patches/86_security_CVE-2009-2694.patch: properly destroy
      slpmsg in libpurple/protocols/{msn,msnp9}/slplink.c.
    - CVE-2009-2694

 -- Marc Deslauriers <email address hidden> Wed, 19 Aug 2009 12:50:44 -0400

pidgin (1:2.5.2-0ubuntu1.3) intrepid-security; urgency=low

  * SECURITY UPDATE: denial of service via ICQWebMessage message type in
    OSCAR protocol. (LP: #393736)
    - debian/patches/85_security_CVE-2009-1889.patch: make the check better
      in libpurple/protocols/oscar/oscar.c, only allocate memory if len is
      valid in libpurple/protocols/oscar/bstream.c.
    - CVE-2009-1889

 -- Marc Deslauriers <email address hidden> Fri, 03 Jul 2009 11:12:31 -0400

Philip Wyett (philwyett)
visibility: private → public
Revision history for this message
Philip Wyett (philwyett) wrote :
Revision history for this message
Philip Wyett (philwyett) wrote :

This version has run fine since the build and install.

This morning it will be superseded by 1.5~hardy1 that adds a ported patch that fixes...

https://bugs.launchpad.net/pidgin/+bug/389322?comments=all (The yahoo login failure issue)

This is a drop in patch for intrepid and hardy.

Dan Streetman (ddstreet)
Changed in hardy-backports:
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.