-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-8523 2010-05-13 18:51:04 --------------------------------------------------------------------------------
Name : pidgin Product : Fedora 11 Version : 2.7.0 Release : 2.fc11 URL : http://pidgin.im/ Summary : A Gtk+ based multiprotocol instant messaging client Description : Pidgin allows you to talk to anyone using a variety of messaging protocols including AIM, MSN, Yahoo!, Jabber, Bonjour, Gadu-Gadu, ICQ, IRC, Novell Groupwise, QQ, Lotus Sametime, SILC, Simple and Zephyr. These protocols are implemented using a modular, easy to use design. To use a protocol, just add an account using the account editor. Pidgin supports many common features of other clients, as well as many unique features, such as perl scripting, TCL scripting and C plugins. Pidgin is not affiliated with or endorsed by America Online, Inc., Microsoft Corporation, Yahoo! Inc., or ICQ Inc. -------------------------------------------------------------------------------- Update Information: 2.7.0 with new features, bug fixes and a security fix for CVE-2010-1624 Full Upstream ChangeLog: * http://developer.pidgin.im/wiki/ChangeLog Fedora packaging changes: * Use System SSL Certificates * Add additional dependencies for Voice + Video -------------------------------------------------------------------------------- ChangeLog: * Thu May 20 2010 Stu Tomlinson <[email protected]> 2.7.0-2 - Upstream backports: 3c30f64efedafc379b6536852bbb3b6ef5f1f6c9 - fix for receiving HTML on ICQ 13fbe0815f84d5b3c001947559f5818c10275f4c - prevent null deref on disconnecting account (#592750) c4a874926d07b8597db4b78a181a89cf720a8418 - fix blinking tray icon on new message (#592691) cfe0e649dda34d9252d40d8f67e445336a247998 - prevent race condition on Yahoo! login e3dd36706068f3b8eabd630ff71d270c145cce42 - fix crash in Oscar (#548128) 13fbe0815f84d5b3c001947559f5818c10275f4c - fix crash during network disconnect (#592750) * Thu May 13 2010 Stu Tomlinson <[email protected]> - 2.7.0-1 - 2.7.0 with features, bug fixes and a security fix: CVE-2010-1624 (#591806) - Use System SSL Certificates (#576721) - Add additional dependencies for Voice + Video (#581343) - Upstream backport: 87ada76abf90c44e615679efc5f8128bb941bba1 Reduce MSN traffic * Thu Mar 4 2010 Warren Togami <[email protected]> - 2.6.6-2 - Upstream backports: 0e3079d15adeb12c1e57ceaf5bf037f9b71c8abd Fix AIM SSL clientLogin b14ee507e932a395a0e1f29298af162c8614ca0f Fix AIM clientLogin with proxy * Tue Feb 16 2010 Warren Togami <[email protected]> - 2.6.6-1 - 2.6.6 with security and numerous minor bug fixes CVE-2010-0277 CVE-2010-0420 CVE-2010-0423 - Bug #528796: Get rid of #!/usr/bin/env python * Fri Jan 8 2010 Warren Togami <[email protected]> - 2.6.5-2 - 2.6.5 - CVE-2010-0013 - Other bug fixes - Fix build with old gcc versions (RHEL4) * Tue Dec 8 2009 Warren Togami <[email protected]> - 2.6.4-4 - temporarily disable evolution integration in F13 until it is fixed * Wed Dec 2 2009 Warren Togami <[email protected]> 2.6.4-2 - disable SILC in EL6 builds * Mon Nov 30 2009 Warren Togami <[email protected]> 2.6.4-1 - 2.6.4 * Mon Oct 19 2009 Warren Togami <[email protected]> 2.6.3-2 - Upstream backport: 3abad7606f4a2dfd1903df796f33924b12509a56 msn_servconn_disconnect-crash * Fri Oct 16 2009 Warren Togami <[email protected]> 2.6.3-1 - 2.6.3 CVE-2009-3615 * Wed Sep 9 2009 Warren Togami <[email protected]> 2.6.2-2 - Upstream backports: 97e003ed2bc2bafbb993693c9ae9c6d667731cc1 aim-buddy-status-grab 37aa00d044431100d37466517568640cb082680c yahoo-buddy-idle-time 40005b889ee276fbcd0a4e886a68d8a8cce45698 yahoo-status-change-away cb46b045aa6e927a3814d9053c2b1c0f08d6fa62 crash-validate-jid * Sun Sep 6 2009 Stu Tomlinson <[email protected]> 2.6.2-1.1 - VV support needs to be explicitly disabled on F10 * Sun Sep 6 2009 Stu Tomlinson <[email protected]> 2.6.2-1 - 2.6.2 Fixes a number of crashes - CVE-2009-2703, CVE-2009-3083, CVE-2009-3084, CVE-2009-3085 * Wed Aug 19 2009 Warren Togami <[email protected]> 2.6.1-1 - 2.6.1: Fix a crash when some users send you a link in a Yahoo IM * Tue Aug 18 2009 Warren Togami <[email protected]> 2.6.0-1 - CVE-2009-2694 - Voice and Video support via farsight2 (Fedora 11+) - Numerous other bug fixes * Thu Aug 6 2009 Warren Togami <[email protected]> 2.6.0-0.11.20090812 - new snapshot at the request of maiku * Thu Aug 6 2009 Warren Togami <[email protected]> 2.6.0-0.10.20090806 - new snapshot - theoretically better sound quality in voice chat * Tue Aug 4 2009 Warren Togami <[email protected]> 2.6.0-0.9.20090804 - new snapshot * Mon Jul 27 2009 Warren Togami <[email protected]> 2.6.0-0.8.20090727 - new snapshot * Mon Jul 27 2009 Stu Tomlinson <[email protected]> 2.6.0-0.6.20090721 - Prevent main libpurple & pidgin packages depending on perl (#513902) * Sun Jul 26 2009 Fedora Release Engineering <[email protected]> - 2.6.0-0.5.20090721 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Wed Jul 22 2009 Warren Togami <[email protected]> 2.6.0-0.4.20090721 - rebuild * Tue Jul 21 2009 Warren Togami <[email protected]> 2.6.0-0.3.20090721 - prevent crash with no camera when closing vv window * Tue Jul 21 2009 Warren Togami <[email protected]> 2.6.0-0.1.20090721 - 2.6.0 snapshot with voice and video support via farsight2 * Sat Jul 11 2009 Stu Tomlison <[email protected]> 2.5.8-2 - Backport patch from upstream to enable NSS to recognize root CA certificates that use MD2 & MD4 algorithms in their signature, as used by some MSN and XMPP servers * Sun Jun 28 2009 Warren Togami <[email protected]> 2.5.8-1 - 2.5.8 with several important bug fixes * Mon Jun 22 2009 Warren Togami <[email protected]> 2.5.7-2 - glib2 compat with RHEL-4 * Sat Jun 20 2009 Warren Togami <[email protected]> 2.5.7-1 - 2.5.7 with Yahoo Protocol 16 support * Wed May 20 2009 Stu Tomlinson <[email protected]> 2.5.6-1 - 2.5.6 * Mon Apr 20 2009 Warren Togami <[email protected]> 2.5.5-3 - F12+ removed krb4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #589973 - CVE-2010-1624 Pidgin: MSN SLP emoticon DoS (NULL pointer dereference) https://bugzilla.redhat.com/show_bug.cgi?id=589973 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pidgin' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
