Pidgin is an instant messaging program which can log in to multipleaccounts on multiple instant messaging networks simultaneously.A directory traversal flaw was discovered in Pidgin's MSN protocolimplementation. A remote attacker could send a specially-crafted emoticonimage download request that would cause Pidgin to disclose an arbitraryfile readable to the user running Pidgin. (CVE-2010-0013)These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin releasenotes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLogAll Pidgin users should upgrade to these updated packages, which correctthis issue. Pidgin must be restarted for this update to take effect.