LWN.net Logo

Fedora alert FEDORA-2010-9679 (emesene)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 12 Update: emesene-1.6.2-1.fc12
Date:  Thu, 10 Jun 2010 19:22:33 +0000
Message-ID:  <20100610192233.C1B65111A7B@bastion02.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-9679 2010-06-08 18:41:20 -------------------------------------------------------------------------------- Name : emesene Product : Fedora 12 Version : 1.6.2 Release : 1.fc12 URL : http://emesene.org Summary : Instant messaging client for Windows Live Messenger network Description : Emesene is a MSN Messenger client writed in Python and GTK. The main idea is to make a client similar to the official MSN Messenger client but kepping it simple and with a nice GUI. Emesene is a python/gtk MSN messenger clone, it uses msnlib (MSNP9) and try to be a nice looking and simple MSN client. You can login, send formated messages, smilies, use autoreply, change status, change nick, send nudges and all the stuff you can do in a normal MSN client except, file transfers,custom emoticons and display picture. -------------------------------------------------------------------------------- Update Information: emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 8 2010 Rahul Sundaram <sundaram@fedoraproject.org> - 1.6.2-1 - Update to 1.6.2. Resolves rhbz#601402 CVE-2010-2053 - Update spec to match current guidelines * Fri Jan 15 2010 Allisson Azevedo <allisson@gmail.com> - 1.6-1 - Update to 1.6. -------------------------------------------------------------------------------- References: [ 1 ] Bug #601401 - CVE-2010-2053 emesene: symlink vulnerability allows overwriting arbitrary files https://bugzilla.redhat.com/show_bug.cgi?id=601401 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update emesene' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds