-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 27 Jun 2016 19:05:23 +1000 Source: pidgin Binary: libpurple0 pidgin pidgin-data pidgin-dev pidgin-dbg finch finch-dev libpurple-dev libpurple-bin Architecture: source all i386 Version: 2.10.10-1~deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Ari Pollak <ari@debian.org> Changed-By: Brian May <bam@debian.org> Description: finch - text-based multi-protocol instant messaging client finch-dev - text-based multi-protocol instant messaging client - development libpurple-bin - multi-protocol instant messaging library - extra utilities libpurple-dev - multi-protocol instant messaging library - development files libpurple0 - multi-protocol instant messaging library pidgin - graphical multi-protocol instant messaging client for X pidgin-data - multi-protocol instant messaging client - data files pidgin-dbg - Debugging symbols for Pidgin pidgin-dev - multi-protocol instant messaging client - development files Changes: pidgin (2.10.10-1~deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2016-2376.patch: Fix TALOS-CAN-0118 * CVE-2016-2377.patch: TALOS-CAN-0119 * CVE-2016-2378.patch: Fix for TALOS-CAN-0120 * CVE-2016-2380.patch: Fix for TALOS-CAN-0123 * CVE-2016-4323.patch: Fix TALOS-CAN-0128 * CVE-2016-2365: Fix TALOS-CAN-0133 * CVE-2016-2366: Fix TALOS-CAN-0134 * CVE-2016-2367-1.patch: Fix chunk decoding errors (TALOS-2016-0135) * CVE-2016-2367-2.patch: Check the chunk header (TALOS-2016-0135) * CVE-2016-2367-3.patch: Add a check to make sure the file can have a chunk (TALOS-2016-0135) * CVE-2016-2368-1.patch: Fix for TALOS-CAN-0136 part 1 * CVE-2016-2368-2.patch: Fix for TALOS-CAN-0136 part 2 * CVE-2016-2369.patch: Fix for TALOS-CAN-0137 * CVE-2016-2370.patch: Fix for TALOS-CAN-0138 * CVE-2016-2371.patch: Fix TALOS-CAN-0139 * CVE-2016-2372/TALOS-2016-0140: Fixed by CVE-2016-2367-2.patch * CVE-2016-2373.patch: Fix TALOS-CAN-0141 * CVE-2016-2374.patch: Fix for TALOS-CAN-0142 * CVE-2016-2375.patch: Fix for TALOS-CAN-0143 Checksums-Sha1: eb7c2859af1d2aea27dde621506553f318470332 2750 pidgin_2.10.10-1~deb7u2.dsc 81267c35c8d27f2c62320b564fc11af2cc1f3a4a 9409485 pidgin_2.10.10.orig.tar.bz2 2783563a6244ef3be13c276d28869c96d2fbeab5 89985 pidgin_2.10.10-1~deb7u2.debian.tar.gz 812384652fddaf99c688e4126e159581a786a8ca 4710990 pidgin-data_2.10.10-1~deb7u2_all.deb 8a0fd9cd5f55f0bc7d55f7f8c2a4275611dad409 2189190 pidgin-dev_2.10.10-1~deb7u2_all.deb 243a5258bbea361e6ce4ba0e52c692f07673f32f 142064 finch-dev_2.10.10-1~deb7u2_all.deb de51454260373c89279a96ce904daba274efe668 253856 libpurple-dev_2.10.10-1~deb7u2_all.deb 7568d2057d298300f300ea6fcbd881afc78c144f 120598 libpurple-bin_2.10.10-1~deb7u2_all.deb 509d27f51c75ea1afb86f29c24d1798ed889f52d 1474836 libpurple0_2.10.10-1~deb7u2_i386.deb d7748e217c2255649f76e21153cb9a89ab2f0e40 612048 pidgin_2.10.10-1~deb7u2_i386.deb 2e4aa6e90696de50223c04697ae2414188100bfd 5400668 pidgin-dbg_2.10.10-1~deb7u2_i386.deb b42c2f7573388b9dd2ae974cb016e2f589970a34 310924 finch_2.10.10-1~deb7u2_i386.deb Checksums-Sha256: 0fb6c0644f5a2405d085de0290cb08f60eb25855436c77be22464071a18372fd 2750 pidgin_2.10.10-1~deb7u2.dsc dc6b95512eaec75aef170aabce471491fc70584932599dfead20f1f1c45c822d 9409485 pidgin_2.10.10.orig.tar.bz2 7d72b55a8c3a29d4f5272cfb8e9abe68d736f317897e8d5629edbf9c42452b02 89985 pidgin_2.10.10-1~deb7u2.debian.tar.gz e3c4d048131c0af05c8f01ba4ed171bd9f2bb84bc48d52e96912b61400d71892 4710990 pidgin-data_2.10.10-1~deb7u2_all.deb c17c697082639f3fe3ebde337cfc20c03d37d17fbed5e458e87df8d7310e5c54 2189190 pidgin-dev_2.10.10-1~deb7u2_all.deb 55f5be088ced8fac08792ee25ed2fad19f63aa73010d3f9febcab9abaee792fa 142064 finch-dev_2.10.10-1~deb7u2_all.deb eb0f2df8bf702f4f91d705d49837cac10ccba422534088bd47cc67dbea55ece7 253856 libpurple-dev_2.10.10-1~deb7u2_all.deb 8742b9c660e276187953623d1c6e5d8e491697470582408244baea48436393bc 120598 libpurple-bin_2.10.10-1~deb7u2_all.deb 259605a2d6c5d7822c369086149146bacae7ab8efd3afe8c8252e1769b6dd1ff 1474836 libpurple0_2.10.10-1~deb7u2_i386.deb 48955b204e2a024bad2f011bd20e3ee20c91400630ea43501be8576a10f09b9e 612048 pidgin_2.10.10-1~deb7u2_i386.deb 7128a73e21ab5a872a01858d16461ac8a352544469c335a924c49da05715e384 5400668 pidgin-dbg_2.10.10-1~deb7u2_i386.deb f49f11cfd396aff5cd855ed7b3e448f85506ee4390b4a6c9cae5c2c899713ef3 310924 finch_2.10.10-1~deb7u2_i386.deb Files: 2884c9c6e7b03a6300f5e0fd9fffa78b 2750 net optional pidgin_2.10.10-1~deb7u2.dsc 5030d4750c73b211c7e82bb67ea3d016 9409485 net optional pidgin_2.10.10.orig.tar.bz2 5ad077db2bf1f41d0455fc3927592507 89985 net optional pidgin_2.10.10-1~deb7u2.debian.tar.gz b7f2ff1fd5b19fac981f97d4e7aa7820 4710990 net optional pidgin-data_2.10.10-1~deb7u2_all.deb 266ec85dd309e9fea5a55e0f8c70de2a 2189190 devel optional pidgin-dev_2.10.10-1~deb7u2_all.deb f9e528a0139d8110e9f207bdb7b855d4 142064 devel optional finch-dev_2.10.10-1~deb7u2_all.deb 8c0981bcf7c7872c0c61be9cbf071166 253856 libdevel optional libpurple-dev_2.10.10-1~deb7u2_all.deb fd28b21d7da85e60373dc81df41039f2 120598 net optional libpurple-bin_2.10.10-1~deb7u2_all.deb 21ce0a3eb665e33fde7d4e164e4b5284 1474836 net optional libpurple0_2.10.10-1~deb7u2_i386.deb c65cbe12acf7927374d7f0e23075a14f 612048 net optional pidgin_2.10.10-1~deb7u2_i386.deb 765d6f6019c24028ba22d1aa3eb7c8de 5400668 debug extra pidgin-dbg_2.10.10-1~deb7u2_i386.deb 16d7dd71134b520ecebd2370c57062ab 310924 net optional finch_2.10.10-1~deb7u2_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXeiduAAoJEBeEV3+BH26sCigP/01qCEYh7S5mhHz3DBfJ1AtW nERN82iTyNXFkAS/jFyoUFXw+nzra+wzm8qQJXNtFqD3QQTDOa6hxLdoxFT990Aa G546L7uLhbbNHcKgrBqfy9ueMWYy/lkocW3kOlJd2jiAskQvGSLqoelJo3KLX/Xa yrTVU+mKQkmLGbYjp7GGDzOAlZBd+VB/c7O57CAcl4VheogONTfRt/iBK7g/wb2V hsVYc3V3dRg4FbLnvIxskDp+pDh/PnB2IAmHl/Df9oIa14Cy67N+NYMqWVi1ucVW bbMe8EAcideC0ewBkkBxxzs8Aopgegvivrw6jyuSB+OVBUloc4roTMiB5f/O9QsX kOUCR01qSxW4iy6ywGHRkh33c/x6OHPkvTUYc5gO629E7Xz3oH8D6ejmePQX41bM 97ZdPdzUc+lGUmdMvauHgf/AsxnZsOnvdb0pP3wYNr6+JHAm8LAIKAkMDuRYYCsT LqzPEIPgng+MtZf3mUdtcRJljgwFSVA+SL/YKWw3n2WL8GwkIcZ4cRxZ1fhNLa5d QqliP41afNwpzTsGNr2OBli4xoMTztw196Jt7VAyKt2i1kYP5Qo+gbU7FUiyw6M9 57IxpH2UquZrKFywArjb6Xq8NAQenOnRL1VzP3hwcbB/90X/iivT0DRE1vfv0fvC 6acvrfQMKwGTuJ5YO0G7 =Unqq -----END PGP SIGNATURE-----