-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 04 Mar 2017 16:44:08 -0500 Source: pidgin Binary: libpurple0 pidgin pidgin-data pidgin-dev pidgin-dbg finch finch-dev libpurple-dev libpurple-bin Architecture: source all amd64 Version: 2.11.0-0+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Ari Pollak <ari@debian.org> Changed-By: Luciano Bello <luciano@debian.org> Description: finch - text-based multi-protocol instant messaging client finch-dev - text-based multi-protocol instant messaging client - development libpurple-bin - multi-protocol instant messaging library - extra utilities libpurple-dev - multi-protocol instant messaging library - development files libpurple0 - multi-protocol instant messaging library pidgin - graphical multi-protocol instant messaging client for X pidgin-data - multi-protocol instant messaging client - data files pidgin-dbg - Debugging symbols for Pidgin pidgin-dev - multi-protocol instant messaging client - development files Changes: pidgin (2.11.0-0+deb8u2) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2017-2640: Out-of-bound memory access fixed by ported upstream patch from 2.12.0 Checksums-Sha1: 279ea676cf3329597d600a4c6df7b4cd09a8d19f 2834 pidgin_2.11.0-0+deb8u2.dsc e086a1910a71630174eba2ee47e0f40ba814dd37 62472 pidgin_2.11.0-0+deb8u2.debian.tar.xz e03f0a2bae6518ce15d4184419052afc4b8320b9 4839944 pidgin-data_2.11.0-0+deb8u2_all.deb 8c9a1fc0b245ad59ab0ce6703d2ba53284d44f85 2317372 pidgin-dev_2.11.0-0+deb8u2_all.deb aaf94c6008893a0b6eedab650631e9a4d2dea98a 143084 finch-dev_2.11.0-0+deb8u2_all.deb 13edd56d8c58506ae2df709b26eb42a6640c0c0e 257350 libpurple-dev_2.11.0-0+deb8u2_all.deb afeb630331315405c64648783f1a1ebceec2c979 122094 libpurple-bin_2.11.0-0+deb8u2_all.deb c79291e5ec838547313c08d0919b9868d4fe3930 1392498 libpurple0_2.11.0-0+deb8u2_amd64.deb 2fcc95ab13769a5f4303f9077da37abc4f439cd9 614748 pidgin_2.11.0-0+deb8u2_amd64.deb 333aa54afe7c0173e0e725f99c8271133683d0dd 5020156 pidgin-dbg_2.11.0-0+deb8u2_amd64.deb 5b8a8beff63f1a0b8b85591a3f822bbd59ad2d5b 310966 finch_2.11.0-0+deb8u2_amd64.deb Checksums-Sha256: 5e52f45a32c78373e344fdd4d782018f66545a135b63651035b8f29df7282b25 2834 pidgin_2.11.0-0+deb8u2.dsc bd47fa4173f05dc31767f3e070c95cf4c9c3433a88745272e470941c25daadd0 62472 pidgin_2.11.0-0+deb8u2.debian.tar.xz 50a01f7b6bbc47afb3663027bd2d9ec397ad04536dcf94d1030a402093dd43b0 4839944 pidgin-data_2.11.0-0+deb8u2_all.deb 8bd4cacf4dc684920c2c30944ab0ee2c3c1c69186beb46cfece8bdd0336e8185 2317372 pidgin-dev_2.11.0-0+deb8u2_all.deb 5f77377a67b74c8997a0d06bbea9e72407e1210566b0cbcf0941846889fb6317 143084 finch-dev_2.11.0-0+deb8u2_all.deb 6b9064f3a62202e1f26b929501d83d67bb5fe96f850d12956e795fe38c8df26a 257350 libpurple-dev_2.11.0-0+deb8u2_all.deb 78a4f2a11caae8ad40616f3fd750e32c8eee2cc4e2ff83f42a2ad1741baf14fd 122094 libpurple-bin_2.11.0-0+deb8u2_all.deb 82d68f8ff47592e07f132dba0a7beeb1e900797dd215b8cdf9a1b703963d2e7e 1392498 libpurple0_2.11.0-0+deb8u2_amd64.deb f95689bb7f7c0c543c69caecbdd58bddcd955f054195e3097dff37aabd4b13a1 614748 pidgin_2.11.0-0+deb8u2_amd64.deb 3d15304eb980aca39c5f9aa7cc381d6a2ea862ad3d7c146e9fe9eb7845874c19 5020156 pidgin-dbg_2.11.0-0+deb8u2_amd64.deb 85f6afa101e9a3ed64cd1625e0f86d2a4258ee542532a51767b57e3ba82cb98e 310966 finch_2.11.0-0+deb8u2_amd64.deb Files: b3f216672f6e7ff904a6330a3573b30e 2834 net optional pidgin_2.11.0-0+deb8u2.dsc b7061dca347b963440dda7448a27e726 62472 net optional pidgin_2.11.0-0+deb8u2.debian.tar.xz b309ed0c2714198dac8d7ff5efcfa528 4839944 net optional pidgin-data_2.11.0-0+deb8u2_all.deb 19fddc26411290ea492e1aa9043fe50a 2317372 devel optional pidgin-dev_2.11.0-0+deb8u2_all.deb 0b82d0bc295efb38f9bbb008ba6d61fc 143084 devel optional finch-dev_2.11.0-0+deb8u2_all.deb 7e749ca166e7ec756710796a6f20401f 257350 libdevel optional libpurple-dev_2.11.0-0+deb8u2_all.deb ad391e19308157812aecd5b472dd40d2 122094 net optional libpurple-bin_2.11.0-0+deb8u2_all.deb 4ba1dbfe47321003a5183cf929459318 1392498 net optional libpurple0_2.11.0-0+deb8u2_amd64.deb e001dcc177e967feb52d69606dbc2542 614748 net optional pidgin_2.11.0-0+deb8u2_amd64.deb c0e2c75364ae8aebd51a3cde74b43ad4 5020156 debug extra pidgin-dbg_2.11.0-0+deb8u2_amd64.deb 43dbfc4dab96eb2282e32f451122e548 310966 net optional finch_2.11.0-0+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJYwh0eAAoJEG7C3vaP/jd0rTsP/i8CsDsuffuY67CiG9H0pPUe v18OYHVE/nZqsRPv4AJUKElfBMPsVua1Gi1NbJ2n5RZDJpCjn5x0abazcrCuWYnI GfT+OAaHAw11Hg1QAcJCb95T5x4kL9s7vVwY6/3ThTHsVLeNnfSdcChII6QQhoA0 RblFFXYcWTDyIrVbJLb5ZyXX2YkmiCVTEF2pL+folfK5s5Q2sP9DuPjeLbAvnTNh QMFNLugPo5X6AdcTKKZxQ8NhwC/RmPQ/mB4ip+KqxTAJFiD8l6s1fXSZni3+Ypmk ESisW6+gIrLcScya/dMZMjtXMNal2DGbiRzlL+EcZuko9bI8/sqbJAvDR7cnPRwD xpBeXzVv6bVzvoETu6CNlQ2zKlP2/HxZ/Ns4cIFM6i/QVmbcl5Z2W1YX4X+O8srI /m3pJCkA3ZZZXOp+dLHl6SVEoCrmOEzwEVFDowsneSeXZyM8if7sbTIWTiV39MiU GtoAvIx2FNAq5HqEKfTJXjNcX0JDcMMWN+H1eFvrS8Lgj+qZF1MZygfjzJmcHQUJ vjW8Oysxo3TmG8Swa8dOG5H+SSb7TeEygbC7H3OxCuljX10RDZBBS6n3vZbr2v/d OMf0XY73qg1whv+yUNTPBIeiWtcjvAjFR23znleLnaV63vAemNJMesh/MASVehxt 55MwNqW0s9kzrFYhu2Nn =utEp -----END PGP SIGNATURE-----