On Thu, 2009-09-03 at 13:14 +0800, Harry Lu wrote:
> According to current plan, Pidgin 2.6.1 will be in OpenSolaris Build
> 124. So please wait for a while.

It might be good to point out that Pidgin < 2.5.9 is vulnerable to an
overflow in libpurple.  See advisory:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694

You don't need to have the attacker in your buddy list to be vulnerable.

This security hole may be the reason the original poster is concerned.

Reply via email to