security review and patches for libpurple

Evan Schoenberg evan at
Mon Jul 18 12:47:02 EDT 2011

On Jul 18, 2011, at 11:14 AM, Ethan Blanton <elb at> wrote:

> Jacob Appelbaum spake unto us the following wisdom:
>>> With that in mind, I'd like to ask again if there are any objections
>>> to my committing these patches to ipp without embargo or a coordinated
>>> release.  If not, I will land them some time tomorrow.  If anyone even
>>> simply thinks we should wait a few days or get additional input before
>>> landing them, that's fine, too.
>> I would really strongly encourage you to co-ordinate with the Adium
>> folks. It seems to me that they're behind on libpurple updates and any
>> new security releases that don't go into Adium may cause Mac OS X users
>> major trouble.
> I appreciate that input.  There are several Adium developers on the
> security at contact list, so they are in the loop on this.

Indeed. This patch will be included in Adium 1.4.3b2 which will land soon after it is committed upstream. We hope to have the 1.4.3 release follow soon thereafter. 


> Ethan
> _______________________________________________
> security mailing list
> security at

More information about the security mailing list