pidgin/nest
Clone
Summary
Browse
Changes
Graph
Update the ChangeLog for 2.14.13
default
tip
4 days ago, Gary Kramlich
14cc352bb7a2
Update the ChangeLog for 2.14.13
Testing Done:
Ran the site locally.
Reviewed at https://reviews.imfreedom.org/r/3046/
---
title: independent-20110206-00
date: 2011-02-06T00:00:00.000Z
summary: Cipher API information disclosure
discoveredBy: Julia Lawall
fixedInRelease: 2.7.10
type: security
layout: cve
hidden: true
---
### Description
It was discovered that libpurple versions prior to 2.7.10 do not properly clear
certain data structures used in
`libpurple/cipher.c`
prior to freeing. An
attacker could potentially extract partial information from memory regions freed
by libpurple.
### Mitigation
Proper structure clearing has been implemented.