[Pidgin] #10097: JPEG vunerability reports from Sophos AV

Pidgin trac at pidgin.im
Wed Sep 2 22:59:46 EDT 2009


#10097: JPEG vunerability reports from Sophos AV
-------------------------------------------------------------+--------------
 Reporter:  into_311                                         |        Owner:           
     Type:  defect                                           |       Status:  closed   
Milestone:                                                   |    Component:  libpurple
  Version:  2.6.1                                            |   Resolution:  cantfix  
 Keywords:  security, vulnerability, jpeg, jpg, buddy icons  |  
-------------------------------------------------------------+--------------
Changes (by datallah):

  * status:  new => closed
  * resolution:  => cantfix


Comment:

 All this means is that there are some image files (probably your friends'
 buddy icons) that would cause problems on a Windows system with a
 vulnerable GDI.

 Pidgin has no idea about the contents of any of these files, nor about
 what constitutes a JPEG file with the vulnerability, so there isn't
 anything we can do about your friends' buddy icons.

-- 
Ticket URL: <http://developer.pidgin.im/ticket/10097#comment:1>
Pidgin <http://pidgin.im>
Pidgin


More information about the Tracker mailing list