[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-11-24 Thread Launchpad Bug Tracker
This bug was fixed in the package pidgin - 1:2.2.1-1ubuntu4.3 --- pidgin (1:2.2.1-1ubuntu4.3) gutsy-security; urgency=low * SECURITY UPDATE: code execution via integer overflow in the MSN protocol handler (LP: #245770) - debian/patches/99_SECURITY_CVE-2008-2927.patch: fix

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-10-17 Thread db
Has the fix been included into pidgin on ubuntu ? This is a security risk and should be fixed at some point. -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ub

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-23 Thread Bug Watch Updater
** Changed in: pidgin Status: Unknown => Fix Released -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-22 Thread Craig
** Also affects: pidgin via http://developer.pidgin.im/ticket/3381 Importance: Unknown Status: Unknown -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribe

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-22 Thread Bug Watch Updater
** Changed in: pidgin (Debian) Status: Confirmed => Fix Released -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list u

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-08 Thread Alexander Konovalenko
On Fri, Aug 8, 2008 at 02:11, Steven M. Christey wrote: > > On Tue, 5 Aug 2008, Josh Bressers wrote: > >> http://developer.pidgin.im/ticket/6500 >> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434 > > Use CVE-2008-3532, to be updated later. > > - Steve ** CVE added: http://www.cve.mitre.o

Re: [Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Kees Cook
Ah-ha, it appears the request is pending. I found the thread on the oss-security mailing list. -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ub

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Miron Cuperman
I don't think so. I would have done it, but not certain of the procedure. -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing lis

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Kees Cook
Has a CVE been assigned for this design failure? I haven't been able to find one yet. ** Changed in: pidgin (Ubuntu) Status: New => Confirmed -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Miron Cuperman
See also http://developer.pidgin.im/ticket/6500 which includes a patch. -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list u

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Alexander Konovalenko
** Bug watch added: Debian Bug tracker #492434 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434 ** Also affects: pidgin (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=492434 Importance: Unknown Status: Unknown -- Pidgin XMPP TLS/SSL Man in the Middle attack

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-08-05 Thread Bug Watch Updater
** Changed in: pidgin (Debian) Status: Unknown => Confirmed -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu

[Bug 251304] Re: Pidgin XMPP TLS/SSL Man in the Middle attack

2008-07-25 Thread AleksanderAdamowski
See also: http://developer.pidgin.im/ticket/3381 -- Pidgin XMPP TLS/SSL Man in the Middle attack https://bugs.launchpad.net/bugs/251304 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu