diff ChangeLog @ 29074:89b4054deba1

Fix CVE-2010-0423, a denial of service attack due to the parsing of large numbers of smileys. (Discovered by Antti Hayrynen)
author Mark Doliner <mark@kingant.net>
date Tue, 16 Feb 2010 09:02:23 +0000
parents 40623dd0bba0
children cece09dbb119
line wrap: on
line diff
--- a/ChangeLog	Tue Feb 16 08:58:45 2010 +0000
+++ b/ChangeLog	Tue Feb 16 09:02:23 2010 +0000
@@ -27,7 +27,7 @@
 
 	MSN:
 	* Fix CVE-2010-0277, a possible remote crash when parsing an incoming
-	  SLP message.  Discovered by Fabian Yamaguchi.
+	  SLP message.  (Discovered by Fabian Yamaguchi)
 	* File transfer requests will no longer cause a crash if you delete the
 	  file before the other side accepts.
 	* Received files will no longer hold an extra lock after completion,
@@ -74,6 +74,8 @@
 	  Mohta)
 
 	Pidgin:
+	* Fix CVE-2010-0423, a denial of service attack due to the parsing
+	  of large numbers of smileys.  (Discovered by Antti Hayrynen)
 	* Correctly size conversation and status box entries when the
 	  interior-focus style property is diabled. (Gabriel Schulhof)
 	* Correctly handle a multiline text field being required in a