Submitted by MarcDeslauriers on Thu, 2009-08-20 13:35
Referenced CVEs:
CVE-2009-2694
Description:
===========================================================
Ubuntu Security Notice USN-820-1 August 20, 2009
pidgin vulnerability
CVE-2009-2694
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.04 LTS:
pidgin 1:2.4.1-1ubuntu2.6
Ubuntu 8.10:
pidgin 1:2.5.2-0ubuntu1.4
Ubuntu 9.04:
pidgin 1:2.5.5-1ubuntu8.4
After a standard system upgrade you need to restart Pidgin to effect the
necessary changes.
Details follow:
Federico Muttis discovered that Pidgin did not properly handle certain
malformed messages in the MSN protocol handler. A remote attacker could
send a specially crafted message and possibly execute arbitrary code with
user privileges.


