Fedora Account System
Red Hat Associate
Red Hat Customer
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out of bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read. External references: http://www.talosintel.com/reports/TALOS-2016-0123/ http://www.pidgin.im/news/security/?id=96 Upstream fix: https://bitbucket.org/pidgin/main/commits/8172584fd640