Solution
Please Install the Updated Packages.
Insight
Multiple vulnerabilities has been discovered and corrected in pidgin:
A series of specially crafted file transfer requests can cause clients to reference invalid memory. The user must have accepted one of the file transfer requests (CVE-2012-2214).
Incoming messages with certain characters or character encodings can cause clients to crash (CVE-2012-2318).
This update provides pidgin 2.10.4, which is not vulnerable to these issues.
Affected
pidgin on Mandriva Linux 2011.0,
Mandriva Enterprise Server 5.2
Severity
Classification
-
CVE CVE-2012-2214, CVE-2012-2318 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities