<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="ea9754c57ea8497ff369046cb5102727"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="188">
  <id>finch</id>
  <title>pidgin security update</title>
  <release>openSUSE 11.0</release>
  <issued date="1220454610"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=406416" id="406416" title="bug number 406416" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=404163" id="404163" title="bug number 404163" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=405632" id="405632" title="bug number 405632" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=415679" id="415679" title="bug number 415679" type="bugzilla"/>
  </references>
  <description>- specially crafted MSN SLP messages could cause an integer
  overflow in pidgin. Attackers could potentially exploit
  that to execute arbitrary code (CVE-2008-2927).

- overly long file names in MSN file transfers could crash
  pidgin (CVE-2008-2955).

- SSL certifcates were not verfied. Therefore piding didn't
  notice faked certificates (CVE-2008-3532)

Additionally a problem was fixed that prevented gaim
clients from  connecting to the ICQ network after a server
change on July 1st  2008.
</description>
  <pkglist>
    <collection>
        <package name="finch" arch="i586" version="2.4.1" release="28.4">
          <filename>finch-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="finch" arch="ppc" version="2.4.1" release="28.4">
          <filename>finch-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="finch" arch="x86_64" version="2.4.1" release="28.4">
          <filename>finch-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="finch-devel" arch="i586" version="2.4.1" release="28.4">
          <filename>finch-devel-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="finch-devel" arch="ppc" version="2.4.1" release="28.4">
          <filename>finch-devel-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="finch-devel" arch="x86_64" version="2.4.1" release="28.4">
          <filename>finch-devel-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="libpurple" arch="i586" version="2.4.1" release="28.4">
          <filename>libpurple-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="libpurple" arch="ppc" version="2.4.1" release="28.4">
          <filename>libpurple-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="libpurple" arch="x86_64" version="2.4.1" release="28.4">
          <filename>libpurple-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="libpurple-devel" arch="i586" version="2.4.1" release="28.4">
          <filename>libpurple-devel-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="libpurple-devel" arch="ppc" version="2.4.1" release="28.4">
          <filename>libpurple-devel-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="libpurple-devel" arch="x86_64" version="2.4.1" release="28.4">
          <filename>libpurple-devel-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="libpurple-meanwhile" arch="i586" version="2.4.1" release="28.4">
          <filename>libpurple-meanwhile-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="libpurple-meanwhile" arch="ppc" version="2.4.1" release="28.4">
          <filename>libpurple-meanwhile-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="libpurple-meanwhile" arch="x86_64" version="2.4.1" release="28.4">
          <filename>libpurple-meanwhile-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="libpurple-mono" arch="i586" version="2.4.1" release="28.4">
          <filename>libpurple-mono-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="libpurple-mono" arch="ppc" version="2.4.1" release="28.4">
          <filename>libpurple-mono-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="libpurple-mono" arch="x86_64" version="2.4.1" release="28.4">
          <filename>libpurple-mono-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="pidgin" arch="i586" version="2.4.1" release="28.4">
          <filename>pidgin-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="pidgin" arch="ppc" version="2.4.1" release="28.4">
          <filename>pidgin-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="pidgin" arch="x86_64" version="2.4.1" release="28.4">
          <filename>pidgin-2.4.1-28.4.x86_64.rpm</filename>
        </package>
        <package name="pidgin-devel" arch="i586" version="2.4.1" release="28.4">
          <filename>pidgin-devel-2.4.1-28.4.i586.rpm</filename>
        </package>
        <package name="pidgin-devel" arch="ppc" version="2.4.1" release="28.4">
          <filename>pidgin-devel-2.4.1-28.4.ppc.rpm</filename>
        </package>
        <package name="pidgin-devel" arch="x86_64" version="2.4.1" release="28.4">
          <filename>pidgin-devel-2.4.1-28.4.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
