Pidgin: Multiple vulnerabilities Multiple vulnerabilities have been discovered in Pidgin, leading to the remote execution of arbitrary code, unauthorized information disclosure, or Denial of Service. pidgin 2009-10-22 2009-10-22 276000 281545 283324 remote 2.5.9-r1 2.5.9-r1

Pidgin is a client for a variety of instant messaging protocols.

Multiple vulnerabilities were found in Pidgin:

A remote attacker could send specially crafted SLP (via MSN) or ICQ web messages, possibly leading to execution of arbitrary code with the privileges of the user running Pidgin, unauthorized information disclosure, or a Denial of Service.

There is no known workaround at this time.

All Pidgin users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-im/pidgin-2.5.9-r1"
CVE-2009-1376 CVE-2009-1889 CVE-2009-2694 CVE-2009-3026 GLSA 200905-07 a3li keytoaster keytoaster