diff ChangeLog @ 31066:63b9cb97d356

merged from im.pidgin.pidgin
author Yoshiki Yazawa <yaz@honeyplanet.jp>
date Sat, 23 Oct 2010 16:12:36 +0900
parents 762b3b1f019f
children d1efa830ca01
line wrap: on
line diff
--- a/ChangeLog	Sat Oct 16 21:05:34 2010 +0900
+++ b/ChangeLog	Sat Oct 23 16:12:36 2010 +0900
@@ -1,12 +1,18 @@
 Pidgin and Finch: The Pimpin' Penguin IM Clients That're Good for the Soul
 
-version 2.7.4 (MM/DD/YYYY):
+version 2.7.5 (MM/DD/YYYY):
+
+version 2.7.4 (10/20/2010):
 	General:
 	* Fix search path for Tk when compiling on Debian Squeeze. (#12465)
 	* purple-remote now expects and produces UTF-8. (Guillaume Brunerie)
 	  (#12049)
 	* Add Deutsche Telekom, Thawte Primary, and Go Daddy Class 2 root CAs
 	  (#12667, #12668, and #12594)
+	* Fix CVE-2010-3711 by properly validating return values from the
+	  purple_base64_decode() function before using them.
+	* Fix two local crash bugs by properly validating return values from the
+	  purple_base16_decode() function before using them.
 
 	libpurple:
 	* Fall back to an ordinary request if a UI does not support showing a
@@ -71,6 +77,7 @@
 	  connections. (#12532)
 	* Fix sending SMS messages.  The lookup host changed on us.  (Thanks to
 	  todo) (#12688).
+	* Improvements for some file transfer scenarios, but not all.
 
 	Windows:
 	* Bonjour support now requires Apple Bonjour Print Services version