Wed, 19 Aug 2009 00:33:06 +0000
applied changes from 4d001b258a599c18d6d8da7c0f5a46901dabda9c
through fe6176dc97e0ad4cdd2244f7cb76acbf7297cfe7
Plucked this revision from im.pidgin.pidgin
Original commit message:
Any objections to this? I think it's good for us to acknowledge people
who find bugs and tell us about them in detail (they even gave us
a proof of concept script!)
| ChangeLog | file | annotate | diff | comparison | revisions |
--- a/ChangeLog Wed Aug 19 00:28:10 2009 +0000 +++ b/ChangeLog Wed Aug 19 00:33:06 2009 +0000 @@ -214,7 +214,9 @@ Miscellaneous categories. version 2.5.9 (08/18/2009): - * Fix a crash via a specially crafted MSN message (CVE-2009-2694). + * Fix a crash via a specially crafted MSN message (CVE-2009-2694, + thanks to Core Security Technologies for discovering this and + notifying us privately before announcing it). * Fix a crash in Bonjour, MSN, and XMPP when trying to transfer files with NULL names.