-----BEGIN PGP SIGNED MESSAGE----- Hash: RIPEMD160 Format: 1.8 Date: Tue, 12 May 2009 18:54:42 -0400 Source: pidgin Binary: libpurple0 pidgin pidgin-data pidgin-dev pidgin-dbg finch finch-dev libpurple-dev libpurple-bin Architecture: source all amd64 Version: 2.4.3-4lenny2 Distribution: stable-security Urgency: low Maintainer: Ari Pollak <ari@debian.org> Changed-By: Ari Pollak <ari@debian.org> Description: finch - text-based multi-protocol instant messaging client finch-dev - text-based multi-protocol instant messaging client - development libpurple-bin - multi-protocol instant messaging library - extra utilities libpurple-dev - multi-protocol instant messaging library - development files libpurple0 - multi-protocol instant messaging library pidgin - graphical multi-protocol instant messaging client for X pidgin-data - multi-protocol instant messaging client - data files pidgin-dbg - Debugging symbols for Pidgin pidgin-dev - multi-protocol instant messaging client - development files Changes: pidgin (2.4.3-4lenny2) stable-security; urgency=low . * debian/patches/30_CVE-2009-1373.patch: - fix a buffer overflow in XMPP when initiating file transfer with a client and it sends back malformed response * debian/patches/31_CVE-2009-1375.patch: - fix a memory corruption that can sometimes happen if an internal buffer is full when more bytes are available from the network * debian/patches/32_CVE-2009-1376.patch: - fix a buffer overflow in MSN SLP handling Checksums-Sha1: 2b4a3a03ea59d9b79766024887d096c19bae0fbb 1784 pidgin_2.4.3-4lenny2.dsc a4e484aa0748f4ce0ded791ad65ad96940ef7b27 13123610 pidgin_2.4.3.orig.tar.gz fe0e20db2bdbd12150cf7d4c4ee29e8d44c28ea6 67015 pidgin_2.4.3-4lenny2.diff.gz 575e75194d39a650f210eeb9804bada16f0409bb 7018686 pidgin-data_2.4.3-4lenny2_all.deb be2cff274a428ac3a9a0b19338c1ca6809621fe4 193330 pidgin-dev_2.4.3-4lenny2_all.deb 1f27bdc2cebd5453a1cf198b5d75a73a1b312b70 159310 finch-dev_2.4.3-4lenny2_all.deb 9602b08d459db105cd884059653659e0f90a13fb 276786 libpurple-dev_2.4.3-4lenny2_all.deb 719b6f7a2845290d92c2f7ea1e475e12845a2e27 133450 libpurple-bin_2.4.3-4lenny2_all.deb 12f8c7c068535db9cbb0a93ecabbc19f73ec7282 1713090 libpurple0_2.4.3-4lenny2_amd64.deb 882834354c9cce703127f59965e9301a5361b95e 727040 pidgin_2.4.3-4lenny2_amd64.deb 68ecb4395f1d3dbcb352187dbbe0af0037aa6aa7 5669542 pidgin-dbg_2.4.3-4lenny2_amd64.deb 58031d56031aaa1b47f4dd8cc2be96575e87a2dd 347640 finch_2.4.3-4lenny2_amd64.deb Checksums-Sha256: dabc4ccc019589e45b8616796a2dc7995dce205c90989cbef87a235fedf805bd 1784 pidgin_2.4.3-4lenny2.dsc 74b85c40408bdade6727efb2817a7cb5afbeb1e311d7a74fe747dd3c9b03ff6f 13123610 pidgin_2.4.3.orig.tar.gz c68245286a8c1a5370cf071880620e39019ac7d79a39df58a17e097c499b0347 67015 pidgin_2.4.3-4lenny2.diff.gz a381f5f9da4f995d02e534460fae20d121685cdbf8bbd8f8379547003d314439 7018686 pidgin-data_2.4.3-4lenny2_all.deb d8bcda5394d829fb7d76a908a80ba0aecfce5a96e8f1d75e3179e676109765e9 193330 pidgin-dev_2.4.3-4lenny2_all.deb 2f8fdf5897655ccbd172c04dc08a0017d636f261464e9de2e7881e6956843c54 159310 finch-dev_2.4.3-4lenny2_all.deb 695fdee810f2d08acb105a4845a27d645cfcea0339293c0fde0bbffb53f53928 276786 libpurple-dev_2.4.3-4lenny2_all.deb d9e129f7ae1f42436f49507fcad7829a38e4bc2ec393472ab3cff9fd37a5ec99 133450 libpurple-bin_2.4.3-4lenny2_all.deb 05431c46bd64c8998a0a546a398704e34ef65b9ea62a7cbe53f3ea2eaf472d97 1713090 libpurple0_2.4.3-4lenny2_amd64.deb 252a9d9d0a1d0cc2bbfb00267693a7519e6b5f019c8fb03f3ed7f2e933f3f8cb 727040 pidgin_2.4.3-4lenny2_amd64.deb 4c0974a64ccd3edea538453f2c58137599766a97439c3bb6be2877044bbde8f7 5669542 pidgin-dbg_2.4.3-4lenny2_amd64.deb a0a70f09fa93206a649bd12dfc5001e9c54a0f148a00e2558e8677fc99fe4ff5 347640 finch_2.4.3-4lenny2_amd64.deb Files: 3cfbe1a429a466d82ca72b8c1ac40754 1784 net optional pidgin_2.4.3-4lenny2.dsc d0e0bd218fbc67df8b2eca2f21fcd427 13123610 net optional pidgin_2.4.3.orig.tar.gz ca8a67c8a5fbb7952c39e96dfc1c92d6 67015 net optional pidgin_2.4.3-4lenny2.diff.gz 2c14cc93703b4d57f1134280ef019f87 7018686 net optional pidgin-data_2.4.3-4lenny2_all.deb 79cfc03245a6ee2d54f3f1f8f2437f97 193330 devel optional pidgin-dev_2.4.3-4lenny2_all.deb af40922a5c347da65bb3287d7832f488 159310 devel optional finch-dev_2.4.3-4lenny2_all.deb 98123cf4a705addb4f011b1a9aa42806 276786 libdevel optional libpurple-dev_2.4.3-4lenny2_all.deb 0da42200c15fa112d10949833c7b656d 133450 net optional libpurple-bin_2.4.3-4lenny2_all.deb e6224ab98f1d68df3cb10a6c2033bf06 1713090 net optional libpurple0_2.4.3-4lenny2_amd64.deb bef84ab7a06038f3c47532809873823f 727040 net optional pidgin_2.4.3-4lenny2_amd64.deb 1e21b6071f0947ac4153147ff07bb546 5669542 net extra pidgin-dbg_2.4.3-4lenny2_amd64.deb 8d9b18516cb3f836cafed50fca1425dd 347640 net optional finch_2.4.3-4lenny2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEAREDAAYFAkoK1PoACgkQwO+u47cOQDtKEACgkGmpZb+1MhyxzlA347jodPvr qCgAn3dOQvCkKl9GZum1YmR0GXlfQewz =fGW+ -----END PGP SIGNATURE----- Accepted: finch-dev_2.4.3-4lenny2_all.deb to pool/main/p/pidgin/finch-dev_2.4.3-4lenny2_all.deb finch_2.4.3-4lenny2_amd64.deb to pool/main/p/pidgin/finch_2.4.3-4lenny2_amd64.deb libpurple-bin_2.4.3-4lenny2_all.deb to pool/main/p/pidgin/libpurple-bin_2.4.3-4lenny2_all.deb libpurple-dev_2.4.3-4lenny2_all.deb to pool/main/p/pidgin/libpurple-dev_2.4.3-4lenny2_all.deb libpurple0_2.4.3-4lenny2_amd64.deb to pool/main/p/pidgin/libpurple0_2.4.3-4lenny2_amd64.deb pidgin-data_2.4.3-4lenny2_all.deb to pool/main/p/pidgin/pidgin-data_2.4.3-4lenny2_all.deb pidgin-dbg_2.4.3-4lenny2_amd64.deb to pool/main/p/pidgin/pidgin-dbg_2.4.3-4lenny2_amd64.deb pidgin-dev_2.4.3-4lenny2_all.deb to pool/main/p/pidgin/pidgin-dev_2.4.3-4lenny2_all.deb pidgin_2.4.3-4lenny2.diff.gz to pool/main/p/pidgin/pidgin_2.4.3-4lenny2.diff.gz pidgin_2.4.3-4lenny2.dsc to pool/main/p/pidgin/pidgin_2.4.3-4lenny2.dsc pidgin_2.4.3-4lenny2_amd64.deb to pool/main/p/pidgin/pidgin_2.4.3-4lenny2_amd64.deb