oss-sec mailing list archives
Re: CVE request: Pidgin crash
From: Josh Bressers <bressers () redhat com>
Date: Mon, 22 Aug 2011 16:03:46 -0400 (EDT)
----- Original Message -----
2011/8/22 Moritz Mühlenhoff <jmm () inutil org>:On Mon, Aug 22, 2011 at 02:55:34AM -0400, Huzaifa Sidhpurwala wrote:Hi Mark,Hi! Would it be possible to issue a CVE for a new crash in Pidgin?http://pidgin.im/news/security/?id=53Please use CVE-2011-2942 for this issue. Also looking at http://pidgin.im/news/security it seems two other security issues were also fixed in 2.10.0, do you want CVEs to be assigned for them as well?Please do. Since they're published in the form of upstream advisories we'd like to properly track them in the Debian Security Tracker.That's fine by me. As an upstream developer I don't feel like I have a strong incentive to obtain a CVE. But if it's helpful to packagers, than sure. The two issues in question are discussed here: http://pidgin.im/news/security/?id=54
This is a MSN crash. Use CVE-2011-3184
http://pidgin.im/news/security/?id=55 The second one only affects Pidgin on Microsoft Windows.
Use CVE-2011-3185 for this. Thanks. -- JB
Current thread:
- CVE request: Pidgin crash Mark Doliner (Aug 20)
- Re: CVE request: Pidgin crash Huzaifa Sidhpurwala (Aug 21)
- Re: CVE request: Pidgin crash Huzaifa Sidhpurwala (Aug 22)
- Re: CVE request: Pidgin crash Mark Doliner (Aug 22)
- Re: CVE request: Pidgin crash Mark Doliner (Aug 22)
- Re: CVE request: Pidgin crash Moritz Mühlenhoff (Aug 22)
- Re: CVE request: Pidgin crash Mark Doliner (Aug 22)
- Re: CVE request: Pidgin crash Josh Bressers (Aug 22)
- Re: CVE request: Pidgin crash Huzaifa Sidhpurwala (Aug 22)
- Re: CVE request: Pidgin crash Huzaifa Sidhpurwala (Aug 21)