Bug#563206: pidgin: local file disclosure vulnerability

2010-01-07 Thread Ari Pollak
I've just been informed that this is CVE-2010-0013. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#563206: pidgin: local file disclosure vulnerability

2010-01-04 Thread Ari Pollak
Nico Golde wrote: Hi Ari, are you working on an update? I'd NMU this bug otherwise, the issue sucks for a lot of users. Not yet. Feel free to NMU it. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#563206: pidgin: local file disclosure vulnerability

2010-01-02 Thread Ari Pollak
From upstream: A patch for the file upload vulnerability can be found in 4be2df4f, 3d02401c, and c64a1adc [1, 2, 3]. The fix itself is in [3], but depends on the first two to apply properly (and clean up memory correctly). As a note, when backporting the patch to anything older than 2.6.0, the

Bug#563206: pidgin: local file disclosure vulnerability

2009-12-31 Thread Raphael Geissert
Source: pidgin Version: 2.6.4-1 Severity: grave Tags: security Hi, A vulnerability has been discovered in Pidgin. Here's the description Secunia's SA37953 advisory: Fabian Yamaguchi has discovered a vulnerability in Pidgin, which can be exploited by malicious people to disclose sensitive