Skip to navigation

Security Advisory Moderate: pidgin security update

Advisory: RHSA-2011:1820-1
Type: Security Advisory
Severity: Moderate
Issued on: 2011-12-14
Last updated on: 2011-12-14
Affected Products: RHEL Desktop Workstation (v. 5 client)
RHEL Optional Productivity Applications (v. 5 server)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2011-4601
CVE-2011-4602
CVE-2011-4603

Details

Updated pidgin packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 4 and 5.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An input sanitization flaw was found in the way the AOL Open System for
Communication in Realtime (OSCAR) protocol plug-in in Pidgin, used by the
AOL ICQ and AIM instant messaging systems, escaped certain UTF-8
characters. A remote attacker could use this flaw to crash Pidgin via a
specially-crafted OSCAR message. (CVE-2011-4601)

An input sanitization flaw was found in the way the Pidgin SILC (Secure
Internet Live Conferencing) protocol plug-in escaped certain UTF-8
characters in channel messages. A remote attacker could use this flaw to
crash Pidgin via a specially-crafted SILC message. (CVE-2011-4603)

Multiple NULL pointer dereference flaws were found in the Jingle extension
of the Extensible Messaging and Presence Protocol (XMPP) protocol plug-in
in Pidgin. A remote attacker could use these flaws to crash Pidgin via a
specially-crafted Jingle multimedia message. (CVE-2011-4602)

Red Hat would like to thank the Pidgin project for reporting these issues.
Upstream acknowledges Evgeny Boger as the original reporter of
CVE-2011-4601; Diego Bauche Madero from IOActive as the original reporter
of CVE-2011-4603; and Thijs Alkemade as the original reporter of
CVE-2011-4602.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

Updated packages

RHEL Desktop Workstation (v. 5 client)

SRPMS:
pidgin-2.6.6-5.el5_7.4.src.rpm
File outdated by:  RHSA-2013:0646
    MD5: 665916631ec6d8c4d2bf14716946781b
SHA-256: a50dea14638eb4393f1be2087298aaa84d90b4a3a652b810769f6e30d6e3bb76
 
IA-32:
finch-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: baaf8dbab5091c263705b520df131632
SHA-256: 0a03912fa094a4fab71367a15258b6150d7a237b839578a0d8a91a1cb66d16f4
libpurple-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: f19089a714018aac0d4c57c535351a12
SHA-256: 66ff026b662562c412f53c47fdfede1e4d21c4d0de18f3f47d84de589f77445b
pidgin-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 0ca7cd6136ce028b56bea64b2455056c
SHA-256: 9da3218e87affdd8c4e662fc51126bf45570bc00f63e74677be873b4ebbda02e
 
x86_64:
finch-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: baaf8dbab5091c263705b520df131632
SHA-256: 0a03912fa094a4fab71367a15258b6150d7a237b839578a0d8a91a1cb66d16f4
finch-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: eb8697136aaa6e2c8f8b0c63258ecf1f
SHA-256: e14709f79abd0f296949a8eb1874f915c9b086df9d5e2f77e4545cb047c925b2
libpurple-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: f19089a714018aac0d4c57c535351a12
SHA-256: 66ff026b662562c412f53c47fdfede1e4d21c4d0de18f3f47d84de589f77445b
libpurple-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: eb1845787b2975d0bee98f2e954ea144
SHA-256: 80eea3ee4728c39542ae632244c85fd83da62b730bcd8f7ef357fdf28d2f7bf8
pidgin-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 0ca7cd6136ce028b56bea64b2455056c
SHA-256: 9da3218e87affdd8c4e662fc51126bf45570bc00f63e74677be873b4ebbda02e
pidgin-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: 20c4066027efd1fc7cdf5dec3522ecdb
SHA-256: 1a49942d5d90a73cf5cec0d47dbe1a5a7d8688ec9533a07d90c9ad525a27c76e
 
RHEL Optional Productivity Applications (v. 5 server)

SRPMS:
pidgin-2.6.6-5.el5_7.4.src.rpm
File outdated by:  RHSA-2013:0646
    MD5: 665916631ec6d8c4d2bf14716946781b
SHA-256: a50dea14638eb4393f1be2087298aaa84d90b4a3a652b810769f6e30d6e3bb76
 
IA-32:
finch-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: c369270a0a0d27273e9b2ddc80afefd1
SHA-256: 9057274ae19637369202177f9eeb543202eec0e625577bfe2f3f1a148c3aac22
finch-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: baaf8dbab5091c263705b520df131632
SHA-256: 0a03912fa094a4fab71367a15258b6150d7a237b839578a0d8a91a1cb66d16f4
libpurple-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 3e21968b4a577a0c28dca3eeab5c4792
SHA-256: 59c5caa0aae8d4b078848a11313a3031bf8b5c2d0798eeae78f83995d1668dcd
libpurple-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: f19089a714018aac0d4c57c535351a12
SHA-256: 66ff026b662562c412f53c47fdfede1e4d21c4d0de18f3f47d84de589f77445b
libpurple-perl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: c027253d6e303bf90a61c43098e8827d
SHA-256: 89e962121e68e9c771600a573ead1d664d46325a4a304a898ee7afc24c607633
libpurple-tcl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 1c77241ea2714e8a1ec0e07196083d6c
SHA-256: 01e145617e51124e68cacf446dc2a444baa017538d59549e41321d1b03b65204
pidgin-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 5df717123791a0f1cc9570eb4736288a
SHA-256: f9111c82348a636b41f5238b6d2ff78fcd0f4f7b4e701c196738de9238045af8
pidgin-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 0ca7cd6136ce028b56bea64b2455056c
SHA-256: 9da3218e87affdd8c4e662fc51126bf45570bc00f63e74677be873b4ebbda02e
pidgin-perl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 514634f662a88e4480fa8d103f0df301
SHA-256: 460178992dd89e7fab8338caea7f9253e84f61554e57f9f70b04a5490506a365
 
x86_64:
finch-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: c369270a0a0d27273e9b2ddc80afefd1
SHA-256: 9057274ae19637369202177f9eeb543202eec0e625577bfe2f3f1a148c3aac22
finch-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: 8241d38f6a35ed0cc3208623e22a9bde
SHA-256: 4ff7be555f203a81bb2224e4baa9aa8d8599c255dc8dadcb1a838302a58ad35e
finch-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: baaf8dbab5091c263705b520df131632
SHA-256: 0a03912fa094a4fab71367a15258b6150d7a237b839578a0d8a91a1cb66d16f4
finch-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: eb8697136aaa6e2c8f8b0c63258ecf1f
SHA-256: e14709f79abd0f296949a8eb1874f915c9b086df9d5e2f77e4545cb047c925b2
libpurple-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 3e21968b4a577a0c28dca3eeab5c4792
SHA-256: 59c5caa0aae8d4b078848a11313a3031bf8b5c2d0798eeae78f83995d1668dcd
libpurple-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: 315ee68dc22cbc193b9dfcff2ce09a05
SHA-256: 0f02fc9c464a81bf0e2e68d4ee1f18c256b16dd7d41fec2d83faff04203c295c
libpurple-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: f19089a714018aac0d4c57c535351a12
SHA-256: 66ff026b662562c412f53c47fdfede1e4d21c4d0de18f3f47d84de589f77445b
libpurple-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: eb1845787b2975d0bee98f2e954ea144
SHA-256: 80eea3ee4728c39542ae632244c85fd83da62b730bcd8f7ef357fdf28d2f7bf8
libpurple-perl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: 58d11cd943964b503366fd33cec711a7
SHA-256: fe4c64f64462defeeef0b4d820b796834e37efc54351766a71c77f9482c47701
libpurple-tcl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: c8c71ad08e05b002a9367e6b0eacac0d
SHA-256: 24210de13da6cf6814b8b930e54d54fff9fbaadde33b4cda920ec97c1faddd46
pidgin-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 5df717123791a0f1cc9570eb4736288a
SHA-256: f9111c82348a636b41f5238b6d2ff78fcd0f4f7b4e701c196738de9238045af8
pidgin-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: cc1cce18f18738beab796f802f511172
SHA-256: 8c2e2bf909e12c7767efafbfc8160abf1453ae4b251de362faddd70e6c939db9
pidgin-devel-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2013:0646
    MD5: 0ca7cd6136ce028b56bea64b2455056c
SHA-256: 9da3218e87affdd8c4e662fc51126bf45570bc00f63e74677be873b4ebbda02e
pidgin-devel-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: 20c4066027efd1fc7cdf5dec3522ecdb
SHA-256: 1a49942d5d90a73cf5cec0d47dbe1a5a7d8688ec9533a07d90c9ad525a27c76e
pidgin-perl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2013:0646
    MD5: 2d96b3ccbb7caac7661baedd5f550806
SHA-256: 252148088752c4eca0d35dcbfcb7457c9e9b2153eb24e998d6504c1ec43c9a0a
 
Red Hat Desktop (v. 4)

SRPMS:
pidgin-2.6.6-10.el4.src.rpm     MD5: 931ff58cda5f2950d9ebfd3cbe822f2a
SHA-256: d0b2fa5be038f88b07451631ca35463f3beea1c00d53bd401aa66ae2431f109a
 
IA-32:
finch-2.6.6-10.el4.i386.rpm     MD5: 630812c8db0909c0806dddc7419ec9a1
SHA-256: 91c7f44bc7aaecc51b675c96152765e00ff2eae78c3b9a431ac6fa4aae965163
finch-devel-2.6.6-10.el4.i386.rpm     MD5: 6661df7c6452fe7260f99a5c88c6b27f
SHA-256: 70fa9c5d655048ecad00626f0fb244b28d89e9117b9ee6d303799743bf119c70
libpurple-2.6.6-10.el4.i386.rpm     MD5: c8ccad2236f8a4e3bc7757109399efba
SHA-256: 064bfc7bdedb68b1ea98822d776c909f3df43f27064408a9472849241634b2c8
libpurple-devel-2.6.6-10.el4.i386.rpm     MD5: e5b95f288801efe30e1e63762aa56d4d
SHA-256: 185de5722b31a45ddd9caf6b723ac69c92786e5e0934e391dadc6dde728ebc73
libpurple-perl-2.6.6-10.el4.i386.rpm     MD5: 7473c9ccbb2a83fc8137eba868b6f8b4
SHA-256: 52bf5e2d07731b61f126c3e05727298049c5b98f533525c86578ea77111bf48f
libpurple-tcl-2.6.6-10.el4.i386.rpm     MD5: aaae12955cb52f1e33a29c4a8bdf28b9
SHA-256: b77cb01e9f73018abf227d75e62bf1320f05b772eee6ea614020f51bdf9f51fd
pidgin-2.6.6-10.el4.i386.rpm     MD5: 7c57cbf82b5e22b2bd0a8586f08a42d5
SHA-256: 102802858d35d4cfaa014273eaacebf8324f264c106200425d8c891a4a1685b1
pidgin-devel-2.6.6-10.el4.i386.rpm     MD5: 383179affacc0b4bc82638dea44d600b
SHA-256: 93ae0dd6d5f9c73e2ab2bd50261a98e15e2be2161649a8a1e148c167d054b6f9
pidgin-perl-2.6.6-10.el4.i386.rpm     MD5: bb5c726a93f25bfb7f5cd42d2c52afc4
SHA-256: dcec0216d06de15e2cd67da30a7bffe63999b958dc839f157ee385a935911b17
 
x86_64:
finch-2.6.6-10.el4.x86_64.rpm     MD5: 91812030ed57254db743697c326822e2
SHA-256: f87c11fb306c107aac5a271bde3fab4f018e1e81591d5a7fa8dc575650fb3203
finch-devel-2.6.6-10.el4.x86_64.rpm     MD5: 3a73b47a291e772f022a2007f5ee959d
SHA-256: 9f6883c27c052f9399309e579a35ab4f305678de9546251e5e3f614f429941c5
libpurple-2.6.6-10.el4.x86_64.rpm     MD5: 02710448b709c142692ae2c939fbe70d
SHA-256: 1d3895f2410c10df154d5bf17436c257d3a9aa543783cb84c3bc6e178642e1d4
libpurple-devel-2.6.6-10.el4.x86_64.rpm     MD5: feb56081c60f78c541ecef6852c6b91c
SHA-256: d6866812c25e53c3fc42a228a19f9c3de84043af8720cd073ed799281f7c7cfe
libpurple-perl-2.6.6-10.el4.x86_64.rpm     MD5: e7da0cd4344ec92a0700d14ee0a82f45
SHA-256: 35f3c0a4fa8e5b397ee1887552389a2bec1ff5d52ac921cbf791fcf5af734339
libpurple-tcl-2.6.6-10.el4.x86_64.rpm     MD5: a5139936e7d5d54bca602adb9aa12e3b
SHA-256: f2eb89a44a3bee5482e66cd71870d90396bfda1624db8a0803a5ddae09c78cec
pidgin-2.6.6-10.el4.x86_64.rpm     MD5: bf20671bf31e7ff34e167eac2575b3e2
SHA-256: 7c3d04e5ce45bbd793a2d15f387409371cbd7ef8ad89d959921ae7fe316fc430
pidgin-devel-2.6.6-10.el4.x86_64.rpm     MD5: 52e76004a01d36187703081cd477822d
SHA-256: b6e152203eaab3797518e098d42ff16f28393dac45b1fbe6208d721fb7211873
pidgin-perl-2.6.6-10.el4.x86_64.rpm     MD5: 9e59b951cb5b78c5bcf7d563d385540f
SHA-256: 0473f0e8e9ae4e260b112387930d9a111b987a6322166ea5b9da87382f2508fb
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
pidgin-2.6.6-10.el4.src.rpm     MD5: 931ff58cda5f2950d9ebfd3cbe822f2a
SHA-256: d0b2fa5be038f88b07451631ca35463f3beea1c00d53bd401aa66ae2431f109a
 
IA-32:
finch-2.6.6-10.el4.i386.rpm     MD5: 630812c8db0909c0806dddc7419ec9a1
SHA-256: 91c7f44bc7aaecc51b675c96152765e00ff2eae78c3b9a431ac6fa4aae965163
finch-devel-2.6.6-10.el4.i386.rpm     MD5: 6661df7c6452fe7260f99a5c88c6b27f
SHA-256: 70fa9c5d655048ecad00626f0fb244b28d89e9117b9ee6d303799743bf119c70
libpurple-2.6.6-10.el4.i386.rpm     MD5: c8ccad2236f8a4e3bc7757109399efba
SHA-256: 064bfc7bdedb68b1ea98822d776c909f3df43f27064408a9472849241634b2c8
libpurple-devel-2.6.6-10.el4.i386.rpm     MD5: e5b95f288801efe30e1e63762aa56d4d
SHA-256: 185de5722b31a45ddd9caf6b723ac69c92786e5e0934e391dadc6dde728ebc73
libpurple-perl-2.6.6-10.el4.i386.rpm     MD5: 7473c9ccbb2a83fc8137eba868b6f8b4
SHA-256: 52bf5e2d07731b61f126c3e05727298049c5b98f533525c86578ea77111bf48f
libpurple-tcl-2.6.6-10.el4.i386.rpm     MD5: aaae12955cb52f1e33a29c4a8bdf28b9
SHA-256: b77cb01e9f73018abf227d75e62bf1320f05b772eee6ea614020f51bdf9f51fd
pidgin-2.6.6-10.el4.i386.rpm     MD5: 7c57cbf82b5e22b2bd0a8586f08a42d5
SHA-256: 102802858d35d4cfaa014273eaacebf8324f264c106200425d8c891a4a1685b1
pidgin-devel-2.6.6-10.el4.i386.rpm     MD5: 383179affacc0b4bc82638dea44d600b
SHA-256: 93ae0dd6d5f9c73e2ab2bd50261a98e15e2be2161649a8a1e148c167d054b6f9
pidgin-perl-2.6.6-10.el4.i386.rpm     MD5: bb5c726a93f25bfb7f5cd42d2c52afc4
SHA-256: dcec0216d06de15e2cd67da30a7bffe63999b958dc839f157ee385a935911b17
 
IA-64:
finch-2.6.6-10.el4.ia64.rpm     MD5: dd38510e0a8285cf00c1a633c31cea1c
SHA-256: f1a9de197dfb6e0382719726993bd1aa7a37008c4026d01af7e3ff8bbc19bc06
finch-devel-2.6.6-10.el4.ia64.rpm     MD5: 8a79df0dd3675539aef3d4615b5ca3e8
SHA-256: 09d63bc4d36c6750d0fae8852acd46ad35b220ea5665c59c77eaafca2e4947a6
libpurple-2.6.6-10.el4.ia64.rpm     MD5: 682417504bc8529c67e1dd9322a549dd
SHA-256: 3586b2f690b4f2531032bdf6c9ef66ee6103238ea3827f4aabf6c3aa999d1159
libpurple-devel-2.6.6-10.el4.ia64.rpm     MD5: 7af2ba2ec26d7893ad1475462c5b725f
SHA-256: 8bc7d6c72338ed7db5e61ce95df52eeca45bcb6e09ce32033aab8c2bcef15d76
libpurple-perl-2.6.6-10.el4.ia64.rpm     MD5: 299019e320d1b523363afe3d603704a6
SHA-256: 1b5cd7c461685690cddd361daba04d95b08cda2e6ca9cae636beb76340d643b0
libpurple-tcl-2.6.6-10.el4.ia64.rpm     MD5: f40703389551140375335f04ff8ed90f
SHA-256: 9be07ba4cf0f805cfa587264487a30e946c245b2257aa977f9f129b7b5eccd81
pidgin-2.6.6-10.el4.ia64.rpm     MD5: 3da518ee38cac5533b65aa69d3652739
SHA-256: 6be3917394d3c933c76d7534bf08f635528e264acfc87371b32a4e4f75d5817f
pidgin-devel-2.6.6-10.el4.ia64.rpm     MD5: bf154fe7b662d5e711bffbca887c2801
SHA-256: cbcb02e1d87ed77208c160189e79c546c3f37c64ac10fcec9922ee250efcce51
pidgin-perl-2.6.6-10.el4.ia64.rpm     MD5: 60afb6319957a7bfcb65a2e4bcfe38a3
SHA-256: bd7cb90d9950c343d4bba4415abdef97de377eabc615c3aa151b2150f7ed34ca
 
PPC:
finch-2.6.6-10.el4.ppc.rpm     MD5: 8ba2719c804ed1dd390d8d16117bd0b6
SHA-256: be34bdac54e59c270f1af3888acbf03b47233e488d080f1cd13a47164b3cdb71
finch-devel-2.6.6-10.el4.ppc.rpm     MD5: 9bfab71a515c9c92cfb4c4c8b3218a06
SHA-256: df0a3979e2f3e6d19d3b77af65271b08aa18de7de162692ec9be599e6c6f48b5
libpurple-2.6.6-10.el4.ppc.rpm     MD5: c89930d3700ca2bbf7e546a5e8485838
SHA-256: 1b37b693d39d8630cbf2bb011bb7b381ce7f3e577309f5e07e3815c5cf10943b
libpurple-devel-2.6.6-10.el4.ppc.rpm     MD5: 91cd7af62740de13e9e5ba67b0881c40
SHA-256: 50df95b88d2245be9b358248db7f3f5226766989a2f0300dd06d7536e68788c4
libpurple-perl-2.6.6-10.el4.ppc.rpm     MD5: d4d24d7055118f2118b658edd7c38199
SHA-256: 356c67e5e0785ce0499d960326bb8f5b459b50665307b429a7f1fd6d9ea513a0
libpurple-tcl-2.6.6-10.el4.ppc.rpm     MD5: d8f7d5ca1ad4a5e854a436053cd0c9d9
SHA-256: f7c3317292d156ddfc5fb865b3e7b706398fd0da0a8a7e0b660e0cef19286979
pidgin-2.6.6-10.el4.ppc.rpm     MD5: 1b860d7cff83942fc3c315dce29c7e1a
SHA-256: eba3e2108a4c6b07489a7766f20b161faa26ca5c2241f299c3d9db1f5e6faa21
pidgin-devel-2.6.6-10.el4.ppc.rpm     MD5: d52efb4d011ba14f9a05007974941515
SHA-256: 3045b3c010b30e58726ebc0644d22f67799ba8dc9b7f6baec5519b8113929531
pidgin-perl-2.6.6-10.el4.ppc.rpm     MD5: aef970f885a16a37e0f6d6467d1d68b1
SHA-256: 32d8615e6d99e38704e35994432f3ee485ab1324f031437fb6dbc317ef934cfb
 
x86_64:
finch-2.6.6-10.el4.x86_64.rpm     MD5: 91812030ed57254db743697c326822e2
SHA-256: f87c11fb306c107aac5a271bde3fab4f018e1e81591d5a7fa8dc575650fb3203
finch-devel-2.6.6-10.el4.x86_64.rpm     MD5: 3a73b47a291e772f022a2007f5ee959d
SHA-256: 9f6883c27c052f9399309e579a35ab4f305678de9546251e5e3f614f429941c5
libpurple-2.6.6-10.el4.x86_64.rpm     MD5: 02710448b709c142692ae2c939fbe70d
SHA-256: 1d3895f2410c10df154d5bf17436c257d3a9aa543783cb84c3bc6e178642e1d4
libpurple-devel-2.6.6-10.el4.x86_64.rpm     MD5: feb56081c60f78c541ecef6852c6b91c
SHA-256: d6866812c25e53c3fc42a228a19f9c3de84043af8720cd073ed799281f7c7cfe
libpurple-perl-2.6.6-10.el4.x86_64.rpm     MD5: e7da0cd4344ec92a0700d14ee0a82f45
SHA-256: 35f3c0a4fa8e5b397ee1887552389a2bec1ff5d52ac921cbf791fcf5af734339
libpurple-tcl-2.6.6-10.el4.x86_64.rpm     MD5: a5139936e7d5d54bca602adb9aa12e3b
SHA-256: f2eb89a44a3bee5482e66cd71870d90396bfda1624db8a0803a5ddae09c78cec
pidgin-2.6.6-10.el4.x86_64.rpm     MD5: bf20671bf31e7ff34e167eac2575b3e2
SHA-256: 7c3d04e5ce45bbd793a2d15f387409371cbd7ef8ad89d959921ae7fe316fc430
pidgin-devel-2.6.6-10.el4.x86_64.rpm     MD5: 52e76004a01d36187703081cd477822d
SHA-256: b6e152203eaab3797518e098d42ff16f28393dac45b1fbe6208d721fb7211873
pidgin-perl-2.6.6-10.el4.x86_64.rpm     MD5: 9e59b951cb5b78c5bcf7d563d385540f
SHA-256: 0473f0e8e9ae4e260b112387930d9a111b987a6322166ea5b9da87382f2508fb
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
pidgin-2.6.6-5.el5_7.4.src.rpm
File outdated by:  RHSA-2013:0646
    MD5: 665916631ec6d8c4d2bf14716946781b
SHA-256: a50dea14638eb4393f1be2087298aaa84d90b4a3a652b810769f6e30d6e3bb76
 
IA-32:
finch-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: c369270a0a0d27273e9b2ddc80afefd1
SHA-256: 9057274ae19637369202177f9eeb543202eec0e625577bfe2f3f1a148c3aac22
libpurple-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 3e21968b4a577a0c28dca3eeab5c4792
SHA-256: 59c5caa0aae8d4b078848a11313a3031bf8b5c2d0798eeae78f83995d1668dcd
libpurple-perl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: c027253d6e303bf90a61c43098e8827d
SHA-256: 89e962121e68e9c771600a573ead1d664d46325a4a304a898ee7afc24c607633
libpurple-tcl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 1c77241ea2714e8a1ec0e07196083d6c
SHA-256: 01e145617e51124e68cacf446dc2a444baa017538d59549e41321d1b03b65204
pidgin-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 5df717123791a0f1cc9570eb4736288a
SHA-256: f9111c82348a636b41f5238b6d2ff78fcd0f4f7b4e701c196738de9238045af8
pidgin-perl-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 514634f662a88e4480fa8d103f0df301
SHA-256: 460178992dd89e7fab8338caea7f9253e84f61554e57f9f70b04a5490506a365
 
x86_64:
finch-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: c369270a0a0d27273e9b2ddc80afefd1
SHA-256: 9057274ae19637369202177f9eeb543202eec0e625577bfe2f3f1a148c3aac22
finch-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: 8241d38f6a35ed0cc3208623e22a9bde
SHA-256: 4ff7be555f203a81bb2224e4baa9aa8d8599c255dc8dadcb1a838302a58ad35e
libpurple-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 3e21968b4a577a0c28dca3eeab5c4792
SHA-256: 59c5caa0aae8d4b078848a11313a3031bf8b5c2d0798eeae78f83995d1668dcd
libpurple-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: 315ee68dc22cbc193b9dfcff2ce09a05
SHA-256: 0f02fc9c464a81bf0e2e68d4ee1f18c256b16dd7d41fec2d83faff04203c295c
libpurple-perl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: 58d11cd943964b503366fd33cec711a7
SHA-256: fe4c64f64462defeeef0b4d820b796834e37efc54351766a71c77f9482c47701
libpurple-tcl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: c8c71ad08e05b002a9367e6b0eacac0d
SHA-256: 24210de13da6cf6814b8b930e54d54fff9fbaadde33b4cda920ec97c1faddd46
pidgin-2.6.6-5.el5_7.4.i386.rpm
File outdated by:  RHSA-2014:0139
    MD5: 5df717123791a0f1cc9570eb4736288a
SHA-256: f9111c82348a636b41f5238b6d2ff78fcd0f4f7b4e701c196738de9238045af8
pidgin-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: cc1cce18f18738beab796f802f511172
SHA-256: 8c2e2bf909e12c7767efafbfc8160abf1453ae4b251de362faddd70e6c939db9
pidgin-perl-2.6.6-5.el5_7.4.x86_64.rpm
File outdated by:  RHSA-2014:0139
    MD5: 2d96b3ccbb7caac7661baedd5f550806
SHA-256: 252148088752c4eca0d35dcbfcb7457c9e9b2153eb24e998d6504c1ec43c9a0a
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
pidgin-2.6.6-10.el4.src.rpm     MD5: 931ff58cda5f2950d9ebfd3cbe822f2a
SHA-256: d0b2fa5be038f88b07451631ca35463f3beea1c00d53bd401aa66ae2431f109a
 
IA-32:
finch-2.6.6-10.el4.i386.rpm     MD5: 630812c8db0909c0806dddc7419ec9a1
SHA-256: 91c7f44bc7aaecc51b675c96152765e00ff2eae78c3b9a431ac6fa4aae965163
finch-devel-2.6.6-10.el4.i386.rpm     MD5: 6661df7c6452fe7260f99a5c88c6b27f
SHA-256: 70fa9c5d655048ecad00626f0fb244b28d89e9117b9ee6d303799743bf119c70
libpurple-2.6.6-10.el4.i386.rpm     MD5: c8ccad2236f8a4e3bc7757109399efba
SHA-256: 064bfc7bdedb68b1ea98822d776c909f3df43f27064408a9472849241634b2c8
libpurple-devel-2.6.6-10.el4.i386.rpm     MD5: e5b95f288801efe30e1e63762aa56d4d
SHA-256: 185de5722b31a45ddd9caf6b723ac69c92786e5e0934e391dadc6dde728ebc73
libpurple-perl-2.6.6-10.el4.i386.rpm     MD5: 7473c9ccbb2a83fc8137eba868b6f8b4
SHA-256: 52bf5e2d07731b61f126c3e05727298049c5b98f533525c86578ea77111bf48f
libpurple-tcl-2.6.6-10.el4.i386.rpm     MD5: aaae12955cb52f1e33a29c4a8bdf28b9
SHA-256: b77cb01e9f73018abf227d75e62bf1320f05b772eee6ea614020f51bdf9f51fd
pidgin-2.6.6-10.el4.i386.rpm     MD5: 7c57cbf82b5e22b2bd0a8586f08a42d5
SHA-256: 102802858d35d4cfaa014273eaacebf8324f264c106200425d8c891a4a1685b1
pidgin-devel-2.6.6-10.el4.i386.rpm     MD5: 383179affacc0b4bc82638dea44d600b
SHA-256: 93ae0dd6d5f9c73e2ab2bd50261a98e15e2be2161649a8a1e148c167d054b6f9
pidgin-perl-2.6.6-10.el4.i386.rpm     MD5: bb5c726a93f25bfb7f5cd42d2c52afc4
SHA-256: dcec0216d06de15e2cd67da30a7bffe63999b958dc839f157ee385a935911b17
 
IA-64:
finch-2.6.6-10.el4.ia64.rpm     MD5: dd38510e0a8285cf00c1a633c31cea1c
SHA-256: f1a9de197dfb6e0382719726993bd1aa7a37008c4026d01af7e3ff8bbc19bc06
finch-devel-2.6.6-10.el4.ia64.rpm     MD5: 8a79df0dd3675539aef3d4615b5ca3e8
SHA-256: 09d63bc4d36c6750d0fae8852acd46ad35b220ea5665c59c77eaafca2e4947a6
libpurple-2.6.6-10.el4.ia64.rpm     MD5: 682417504bc8529c67e1dd9322a549dd
SHA-256: 3586b2f690b4f2531032bdf6c9ef66ee6103238ea3827f4aabf6c3aa999d1159
libpurple-devel-2.6.6-10.el4.ia64.rpm     MD5: 7af2ba2ec26d7893ad1475462c5b725f
SHA-256: 8bc7d6c72338ed7db5e61ce95df52eeca45bcb6e09ce32033aab8c2bcef15d76
libpurple-perl-2.6.6-10.el4.ia64.rpm     MD5: 299019e320d1b523363afe3d603704a6
SHA-256: 1b5cd7c461685690cddd361daba04d95b08cda2e6ca9cae636beb76340d643b0
libpurple-tcl-2.6.6-10.el4.ia64.rpm     MD5: f40703389551140375335f04ff8ed90f
SHA-256: 9be07ba4cf0f805cfa587264487a30e946c245b2257aa977f9f129b7b5eccd81
pidgin-2.6.6-10.el4.ia64.rpm     MD5: 3da518ee38cac5533b65aa69d3652739
SHA-256: 6be3917394d3c933c76d7534bf08f635528e264acfc87371b32a4e4f75d5817f
pidgin-devel-2.6.6-10.el4.ia64.rpm     MD5: bf154fe7b662d5e711bffbca887c2801
SHA-256: cbcb02e1d87ed77208c160189e79c546c3f37c64ac10fcec9922ee250efcce51
pidgin-perl-2.6.6-10.el4.ia64.rpm     MD5: 60afb6319957a7bfcb65a2e4bcfe38a3
SHA-256: bd7cb90d9950c343d4bba4415abdef97de377eabc615c3aa151b2150f7ed34ca
 
x86_64:
finch-2.6.6-10.el4.x86_64.rpm     MD5: 91812030ed57254db743697c326822e2
SHA-256: f87c11fb306c107aac5a271bde3fab4f018e1e81591d5a7fa8dc575650fb3203
finch-devel-2.6.6-10.el4.x86_64.rpm     MD5: 3a73b47a291e772f022a2007f5ee959d
SHA-256: 9f6883c27c052f9399309e579a35ab4f305678de9546251e5e3f614f429941c5
libpurple-2.6.6-10.el4.x86_64.rpm     MD5: 02710448b709c142692ae2c939fbe70d
SHA-256: 1d3895f2410c10df154d5bf17436c257d3a9aa543783cb84c3bc6e178642e1d4
libpurple-devel-2.6.6-10.el4.x86_64.rpm     MD5: feb56081c60f78c541ecef6852c6b91c
SHA-256: d6866812c25e53c3fc42a228a19f9c3de84043af8720cd073ed799281f7c7cfe
libpurple-perl-2.6.6-10.el4.x86_64.rpm     MD5: e7da0cd4344ec92a0700d14ee0a82f45
SHA-256: 35f3c0a4fa8e5b397ee1887552389a2bec1ff5d52ac921cbf791fcf5af734339
libpurple-tcl-2.6.6-10.el4.x86_64.rpm     MD5: a5139936e7d5d54bca602adb9aa12e3b
SHA-256: f2eb89a44a3bee5482e66cd71870d90396bfda1624db8a0803a5ddae09c78cec
pidgin-2.6.6-10.el4.x86_64.rpm     MD5: bf20671bf31e7ff34e167eac2575b3e2
SHA-256: 7c3d04e5ce45bbd793a2d15f387409371cbd7ef8ad89d959921ae7fe316fc430
pidgin-devel-2.6.6-10.el4.x86_64.rpm     MD5: 52e76004a01d36187703081cd477822d
SHA-256: b6e152203eaab3797518e098d42ff16f28393dac45b1fbe6208d721fb7211873
pidgin-perl-2.6.6-10.el4.x86_64.rpm     MD5: 9e59b951cb5b78c5bcf7d563d385540f
SHA-256: 0473f0e8e9ae4e260b112387930d9a111b987a6322166ea5b9da87382f2508fb
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
pidgin-2.6.6-10.el4.src.rpm     MD5: 931ff58cda5f2950d9ebfd3cbe822f2a
SHA-256: d0b2fa5be038f88b07451631ca35463f3beea1c00d53bd401aa66ae2431f109a
 
IA-32:
finch-2.6.6-10.el4.i386.rpm     MD5: 630812c8db0909c0806dddc7419ec9a1
SHA-256: 91c7f44bc7aaecc51b675c96152765e00ff2eae78c3b9a431ac6fa4aae965163
finch-devel-2.6.6-10.el4.i386.rpm     MD5: 6661df7c6452fe7260f99a5c88c6b27f
SHA-256: 70fa9c5d655048ecad00626f0fb244b28d89e9117b9ee6d303799743bf119c70
libpurple-2.6.6-10.el4.i386.rpm     MD5: c8ccad2236f8a4e3bc7757109399efba
SHA-256: 064bfc7bdedb68b1ea98822d776c909f3df43f27064408a9472849241634b2c8
libpurple-devel-2.6.6-10.el4.i386.rpm     MD5: e5b95f288801efe30e1e63762aa56d4d
SHA-256: 185de5722b31a45ddd9caf6b723ac69c92786e5e0934e391dadc6dde728ebc73
libpurple-perl-2.6.6-10.el4.i386.rpm     MD5: 7473c9ccbb2a83fc8137eba868b6f8b4
SHA-256: 52bf5e2d07731b61f126c3e05727298049c5b98f533525c86578ea77111bf48f
libpurple-tcl-2.6.6-10.el4.i386.rpm     MD5: aaae12955cb52f1e33a29c4a8bdf28b9
SHA-256: b77cb01e9f73018abf227d75e62bf1320f05b772eee6ea614020f51bdf9f51fd
pidgin-2.6.6-10.el4.i386.rpm     MD5: 7c57cbf82b5e22b2bd0a8586f08a42d5
SHA-256: 102802858d35d4cfaa014273eaacebf8324f264c106200425d8c891a4a1685b1
pidgin-devel-2.6.6-10.el4.i386.rpm     MD5: 383179affacc0b4bc82638dea44d600b
SHA-256: 93ae0dd6d5f9c73e2ab2bd50261a98e15e2be2161649a8a1e148c167d054b6f9
pidgin-perl-2.6.6-10.el4.i386.rpm     MD5: bb5c726a93f25bfb7f5cd42d2c52afc4
SHA-256: dcec0216d06de15e2cd67da30a7bffe63999b958dc839f157ee385a935911b17
 
IA-64:
finch-2.6.6-10.el4.ia64.rpm     MD5: dd38510e0a8285cf00c1a633c31cea1c
SHA-256: f1a9de197dfb6e0382719726993bd1aa7a37008c4026d01af7e3ff8bbc19bc06
finch-devel-2.6.6-10.el4.ia64.rpm     MD5: 8a79df0dd3675539aef3d4615b5ca3e8
SHA-256: 09d63bc4d36c6750d0fae8852acd46ad35b220ea5665c59c77eaafca2e4947a6
libpurple-2.6.6-10.el4.ia64.rpm     MD5: 682417504bc8529c67e1dd9322a549dd
SHA-256: 3586b2f690b4f2531032bdf6c9ef66ee6103238ea3827f4aabf6c3aa999d1159
libpurple-devel-2.6.6-10.el4.ia64.rpm     MD5: 7af2ba2ec26d7893ad1475462c5b725f
SHA-256: 8bc7d6c72338ed7db5e61ce95df52eeca45bcb6e09ce32033aab8c2bcef15d76
libpurple-perl-2.6.6-10.el4.ia64.rpm     MD5: 299019e320d1b523363afe3d603704a6
SHA-256: 1b5cd7c461685690cddd361daba04d95b08cda2e6ca9cae636beb76340d643b0
libpurple-tcl-2.6.6-10.el4.ia64.rpm     MD5: f40703389551140375335f04ff8ed90f
SHA-256: 9be07ba4cf0f805cfa587264487a30e946c245b2257aa977f9f129b7b5eccd81
pidgin-2.6.6-10.el4.ia64.rpm     MD5: 3da518ee38cac5533b65aa69d3652739
SHA-256: 6be3917394d3c933c76d7534bf08f635528e264acfc87371b32a4e4f75d5817f
pidgin-devel-2.6.6-10.el4.ia64.rpm     MD5: bf154fe7b662d5e711bffbca887c2801
SHA-256: cbcb02e1d87ed77208c160189e79c546c3f37c64ac10fcec9922ee250efcce51
pidgin-perl-2.6.6-10.el4.ia64.rpm     MD5: 60afb6319957a7bfcb65a2e4bcfe38a3
SHA-256: bd7cb90d9950c343d4bba4415abdef97de377eabc615c3aa151b2150f7ed34ca
 
x86_64:
finch-2.6.6-10.el4.x86_64.rpm     MD5: 91812030ed57254db743697c326822e2
SHA-256: f87c11fb306c107aac5a271bde3fab4f018e1e81591d5a7fa8dc575650fb3203
finch-devel-2.6.6-10.el4.x86_64.rpm     MD5: 3a73b47a291e772f022a2007f5ee959d
SHA-256: 9f6883c27c052f9399309e579a35ab4f305678de9546251e5e3f614f429941c5
libpurple-2.6.6-10.el4.x86_64.rpm     MD5: 02710448b709c142692ae2c939fbe70d
SHA-256: 1d3895f2410c10df154d5bf17436c257d3a9aa543783cb84c3bc6e178642e1d4
libpurple-devel-2.6.6-10.el4.x86_64.rpm     MD5: feb56081c60f78c541ecef6852c6b91c
SHA-256: d6866812c25e53c3fc42a228a19f9c3de84043af8720cd073ed799281f7c7cfe
libpurple-perl-2.6.6-10.el4.x86_64.rpm     MD5: e7da0cd4344ec92a0700d14ee0a82f45
SHA-256: 35f3c0a4fa8e5b397ee1887552389a2bec1ff5d52ac921cbf791fcf5af734339
libpurple-tcl-2.6.6-10.el4.x86_64.rpm     MD5: a5139936e7d5d54bca602adb9aa12e3b
SHA-256: f2eb89a44a3bee5482e66cd71870d90396bfda1624db8a0803a5ddae09c78cec
pidgin-2.6.6-10.el4.x86_64.rpm     MD5: bf20671bf31e7ff34e167eac2575b3e2
SHA-256: 7c3d04e5ce45bbd793a2d15f387409371cbd7ef8ad89d959921ae7fe316fc430
pidgin-devel-2.6.6-10.el4.x86_64.rpm     MD5: 52e76004a01d36187703081cd477822d
SHA-256: b6e152203eaab3797518e098d42ff16f28393dac45b1fbe6208d721fb7211873
pidgin-perl-2.6.6-10.el4.x86_64.rpm     MD5: 9e59b951cb5b78c5bcf7d563d385540f
SHA-256: 0473f0e8e9ae4e260b112387930d9a111b987a6322166ea5b9da87382f2508fb
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

761510 - CVE-2011-4602 pidgin: Multiple NULL pointer deference flaws by processing certain Jingle stanzas in the XMPP protocol plug-in
761517 - CVE-2011-4601 pidgin (libpurple): Invalid UTF-8 string handling in OSCAR messages
766446 - CVE-2011-4603 pidgin: SILC remote crash on channel messages


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/