Pidgin 2.12.0 has been released on March 9, fixing a security issue:
It also fixed Freenode IRC authentication and a certificate validation error with Google that causes some users to not be able to connect (and others to not be able to stay connected).
Protocols for dead services have been removed, and some for upstream protocols that changed have been moved to third-party plugins. It would be nice if we could package the new Yahoo! plugin.
The package in Cauldron/v6 was already updated and I submitted an update to mga5 core/updates_testing.
Thanks! Any chance we can get that Yahoo! plugin packaged?
Updated pidgin packages fix security vulnerability:
A server controlled by an attacker can send an invalid XML that can trigger an
out-of-bound memory access. This might lead to a crash or, in some extreme
cases, to remote code execution in the client-side (CVE-2017-2640).
The pidgin package has been updated to version 2.12.0, which fixes this issue
and other bugs, including certificate validation for the Google Talk protocol.
It also removes protocol plugins for services that are no longer available or
supported. See the upstream ChangeLog for details.
Updated packages in core/updates_testing:
Testing under virtualbox is showing a regression.
Before the update on an m5 i586 install, pidgin is working for irc. After
the update it isn't, and on the modify account dialog, the drop down box
for the protocol does not show any protocols to select from.
Dave, did you update all of the relevant packages?
That's embarrassing. Retested making sure I installed all of the updates, and it's
working. Not sure what I missed before.
Tested before and after installing the updates on both i586 and x86_64.
Validating the update.
advisory feedback =>
advisory MGA5-64-OK MGA5-32-OKCC:
An update for this issue has been pushed to the Mageia Updates repository.