Pidgin versions affected by CVE-2012-2214

Mark Doliner mark at kingant.net
Mon Jun 25 02:36:41 EDT 2012


Hi Tyler.  I just did a little digging and I believe Pidgin 2.6.6 and
2.7.11 are both not vulnerable to CVE-2012-2214
(http://www.pidgin.im/news/security/?id=62).  I believe the
vulnerability was introduced in changeset 31742:e6eb15f2734b on May 3,
2011, which is after 2.7.11 was released.

So you shouldn't need to backport to those builds.  Thanks!
--Mark


More information about the security mailing list