Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 16th, 2011, 09:47 GMT · By Eduard Kovacs

BLOG

Pidgin 2.10.1 Fixes Denial-of-Service Vulnerabilities

SHARE:

Adjust text size:

Pidgin Enlarge picture - Pidgin
The latest variant of the popular open source instant messaging application, Pidgin 2.10.1, comes with several functionality bug fixes, but also with some important ones that resolve flaws which could have allowed an attacker to launch a malicious operation.

One of the issues, reported by Evgeny Boger, could have been taken advantage of to remotely crash the application. This could occur while receiving messages related to requesting or receiving authorization for adding a contact, due to the fact that the Oscar protocol plug-in failed to validate if a piece of text was UTF-8.

The SILC protocol failed at the same thing, in two different pieces of code, when a message was received.

The last security flaw, reported by Thijs Alkemade, refers to the fact that the XMPP protocol pug-in failed to insure that an incoming message contained all the required fields, causing the application to crash.

Since all the prior variants contained the weaknesses, users are advised to update Pidgin to the 2.10.1 version to make sure they’re protected against a potential cyberattack.

Pidgin 2.10.1 for Windows is available for download here
Pidgin 2.10.1 for Linux is available for download here
FILED UNDER:
Pidgin
security update
DOS

TELL US WHAT YOU THINK:

700 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Chrome 16 Comes with 15 Security Fixes

Microsoft Releases December Security Updates, Fix for Duqu Vulnerability Included

Google Removes 22 Malicious 'RuFraud' Apps from Android Market

Google Wallet Stores Too Much Unencrypted Data, Researchers Say

Foxit Reader 5.1.3 Resolves Critical Security Flaw

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM