So I'm not sure everyone saw this: http://developer.pidgin.im/ticket/6500 It's been assigned CVE-2008-3532. So this reminds me of these issues: http://crisp.cs.du.edu/?q=ca2007-1 Has there been any forward movement on them? I'm curious if the patches on that page are considered to be acceptable. Thanks. -- JB