Jump to content

Advisories MDVSA-2010:002: pidgin


paul
 Share

Recommended Posts

A security vulnerability has been identified and fixed in pidgin:

 

Directory traversal vulnerability in slp.c in the MSN protocol

plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows

remote attackers to read arbitrary files via a .. (dot dot) in an

application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request,

a related issue to CVE-2004-0122. NOTE: it could be argued that

this is resultant from a vulnerability in which an emoticon download

request is processed even without a preceding text/x-mms-emoticon

message that announced availability of the emoticon (CVE-2010-0013).

 

This update provides pidgin 2.6.5, which is not vulnerable to this

issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...