Rapid7 Vulnerability & Exploit Database

RHSA-2010:0044: pidgin security update

Back to Search

RHSA-2010:0044: pidgin security update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
01/09/2010
Created
07/25/2018
Added
01/27/2010
Modified
07/04/2017

Description

Pidgin is an instant messaging program which can log in to multipleaccounts on multiple instant messaging networks simultaneously.A directory traversal flaw was discovered in Pidgin's MSN protocolimplementation. A remote attacker could send a specially-crafted emoticonimage download request that would cause Pidgin to disclose an arbitraryfile readable to the user running Pidgin. (CVE-2010-0013)These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin releasenotes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLogAll Pidgin users should upgrade to these updated packages, which correctthis issue. Pidgin must be restarted for this update to take effect.

Solution(s)

  • redhat-upgrade-finch
  • redhat-upgrade-finch-devel
  • redhat-upgrade-libpurple
  • redhat-upgrade-libpurple-devel
  • redhat-upgrade-libpurple-perl
  • redhat-upgrade-libpurple-tcl
  • redhat-upgrade-pidgin
  • redhat-upgrade-pidgin-devel
  • redhat-upgrade-pidgin-perl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;