Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2038-2] New pidgin packages fix regression (1/2)

    From Thijs Kinkhorst@1:229/2 to All on Mon May 17 22:40:01 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2038-2 [email protected] http://www.debian.org/security/ Thijs Kinkhorst
    May 17, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : pidgin
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-0420 CVE-2010-0423
    Debian Bug : 566775 579601

    The packages for Pidgin released as DSA 2038-1 had a regression, as they unintentionally disabled the Zephyr instant messaging protocol. This
    update restores Zephyr functionality. For reference the original
    advisory text below.

    Several remote vulnerabilities have been discovered in Pidgin, a multi
    protocol instant messaging client. The Common Vulnerabilities and
    Exposures project identifies the following problems:

    CVE-2010-0420

    Crafted nicknames in the XMPP protocol can crash Pidgin remotely.

    CVE-2010-0423

    Remote contacts may send too many custom smilies, crashing Pidgin.

    Since a few months, Microsoft's servers for MSN have changed the protocol, making Pidgin non-functional for use with MSN. It is not feasible to port
    these changes to the version of Pidgin in Debian Lenny. This update
    formalises that situation by disabling the protocol in the client. Users
    of the MSN protocol are advised to use the version of Pidgin in the repositories of www.backports.org.

    For the stable distribution (lenny), these problems have been fixed in
    version 2.4.3-4lenny7.

    For the unstable distribution (sid), these problems have been fixed in
    version 2.6.6-1.

    We recommend that you upgrade your pidgin package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.

    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3.orig.tar.gz
    Size/MD5 checksum: 13123610 d0e0bd218fbc67df8b2eca2f21fcd427
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7.diff.gz
    Size/MD5 checksum: 72195 fe0a9dd9d55d642dc77c4f7c678522c8
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7.dsc
    Size/MD5 checksum: 1784 300f72738867fcd326db7f836ac47d67

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-data_2.4.3-4lenny7_all.deb
    Size/MD5 checksum: 7019174 3d1e4508e5543441a5d04a31f03b0979
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-dev_2.4.3-4lenny7_all.deb
    Size/MD5 checksum: 193842 b2c75fc6891adad16add69903ce9762d
    http://security.debian.org/pool/updates/main/p/pidgin/finch-dev_2.4.3-4lenny7_all.deb
    Size/MD5 checksum: 159766 5bb66c4efe6c67eeb33297738799a831
    http://security.debian.org/pool/updates/main/p/pidgin/libpurple-bin_2.4.3-4lenny7_all.deb
    Size/MD5 checksum: 133930 c25806d1d9a07c49c5a3b2fd0b83964c
    http://security.debian.org/pool/updates/main/p/pidgin/libpurple-dev_2.4.3-4lenny7_all.deb
    Size/MD5 checksum: 277224 c169cf3a82bb6a0faf1d285a7377b695

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/p/pidgin/libpurple0_2.4.3-4lenny7_alpha.deb
    Size/MD5 checksum: 1501864 9aa23188e1610834d035e88fd30308b8
    http://security.debian.org/pool/updates/main/p/pidgin/finch_2.4.3-4lenny7_alpha.deb
    Size/MD5 checksum: 369772 a8eb912226cf47f5f74892f0b1110cc4
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7_alpha.deb
    Size/MD5 checksum: 776646 bf0f80658559ab3e4c22356dd47d809d
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-dbg_2.4.3-4lenny7_alpha.deb
    Size/MD5 checksum: 4989752 30e054746fff6d56a9e3b288039ff6c9

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7_amd64.deb
    Size/MD5 checksum: 727950 57554918978a95ea250a8494c9aab433
    http://security.debian.org/pool/updates/main/p/pidgin/libpurple0_2.4.3-4lenny7_amd64.deb
    Size/MD5 checksum: 1429960 2779007da91fe74a1304f3263cd7d53e
    http://security.debian.org/pool/updates/main/p/pidgin/finch_2.4.3-4lenny7_amd64.deb
    Size/MD5 checksum: 348100 d01043df40ed1861c63043b44289984d
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-dbg_2.4.3-4lenny7_amd64.deb
    Size/MD5 checksum: 5101892 af2ea1456eb390f3930e6164108a9c7f

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/p/pidgin/finch_2.4.3-4lenny7_arm.deb
    Size/MD5 checksum: 316624 290e5d8fa14bcc09dde3ce6d326d84bd
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7_arm.deb
    Size/MD5 checksum: 657416 1997d30109a1c86c6c8979ff2e0511ee
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-dbg_2.4.3-4lenny7_arm.deb
    Size/MD5 checksum: 4835872 9f2aaef6679c3b2e27a73240799a7ffa
    http://security.debian.org/pool/updates/main/p/pidgin/libpurple0_2.4.3-4lenny7_arm.deb
    Size/MD5 checksum: 1239516 640fd3ff6c91ac45820581df86965af8

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7_armel.deb
    Size/MD5 checksum: 668000 b0bc286a8e2d74a033ac69b5ed234e6e
    http://security.debian.org/pool/updates/main/p/pidgin/libpurple0_2.4.3-4lenny7_armel.deb
    Size/MD5 checksum: 1243880 88c529b8e9178969c3a3a13e1a8e3230
    http://security.debian.org/pool/updates/main/p/pidgin/finch_2.4.3-4lenny7_armel.deb
    Size/MD5 checksum: 319962 72d956d2c3b6b04dc0aed07e6d99e944
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin-dbg_2.4.3-4lenny7_armel.deb
    Size/MD5 checksum: 4851712 6134571c92b5495489555c01fc4a6d51

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/p/pidgin/libpurple0_2.4.3-4lenny7_hppa.deb
    Size/MD5 checksum: 1522820 023def8c7a3051e1d15030347c99e99d
    http://security.debian.org/pool/updates/main/p/pidgin/pidgin_2.4.3-4lenny7_hppa.deb
    Size/MD5 checksum: 752858 43129b10ef60136293b349614a662972

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Spearb0y
      Sun Jun 7 07:41:05 2026
      from Massachusetts via SSH
    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (0 / 16)
    Uptime: 164:11:19
    Calls: 12,095
    Calls today: 3
    Files: 15,000
    Messages: 6,517,795

© >>> Magnum BBS <<<, 2026