pidgin
203
• the /usr/bin/pear command emitted warnings when the global "error_reporting" PHP configuration
variable was set to the value "E_STRICT". The E_STRICT error-reporting level was introduced into
PHP and PEAR following the release of PHP 5, and has the aim of ensuring that the package is
strictly PHP 5-compatible. With this updated package, /usr/bin/pear no longer emits warnings when
the error-reporting level is set to E_STRICT. (
BZ#461142
1419
)
All users of php-pear are advised to upgrade to this updated package, which resolves these issues.
1.175. pidgin
1.175.1. RHSA-2009:1218: Critical security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1218
1420
Updated pidgin packages that fix a security issue are now available for Red Hat Enterprise Linux 3, 4,
and 5.
This update has been rated as having critical security impact by the Red Hat Security Response
Team.
Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant
messaging networks simultaneously.
Federico Muttis of Core Security Technologies discovered a flaw in Pidgin's MSN protocol handler.
If a user received a malicious MSN message, it was possible to execute arbitrary code with the
permissions of the user running Pidgin. (
CVE-2009-2694
1421
)
Note: Users can change their privacy settings to only allow messages from users on their buddy list to
limit the impact of this flaw.
These packages upgrade Pidgin to version 2.5.9. Refer to the Pidgin release notes for a full list of
changes: http://developer.pidgin.im/wiki/ChangeLog
All Pidgin users should upgrade to these updated packages, which resolve this issue. Pidgin must be
restarted for this update to take effect.
1.175.2. RHSA-2009:1139: Moderate security and bug fix update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:1139
1422
Updated pidgin packages that fix one security issue and one bug are now available for Red Hat
Enterprise Linux 4 and 5.
1421
https://www.redhat.com/security/data/cve/CVE-2009-2694.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...