Mandriva Linux Security Advisory : pidgin (MDVSA-2011:050)
Medium Nessus Plugin ID 52748
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionMultiple vulnerabilities has been identified and fixed in pidgin :
It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.
The Yahoo protocol plugin in libpurple versions 2.6.0 through 2.7.10 do not properly handle malformed YMSG packets, leading to NULL pointer dereferences and application crash (CVE-2011-1091).
Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more:
This update provides pidgin 2.7.11, which is not vulnerable to these issues.
SolutionUpdate the affected packages.