Some XMMP changes that are new in Pidgin 2.10.8 are:
Prevent spoofing of iq replies by verifying that the 'from' address matches the 'to' address of the iq request. (Discovered by Fabian Yamaguchi and Christian Wressnegger of the University of Goettingen, fixed by Thijs Alkemade) (CVE-2013-6483)
Fix crash on some systems when receiving fake delay timestamps with extreme values. (Discovered by Jaime Breva Ribes) (CVE-2013-6477)
Last edited by thisisthedoctor; 01-30-2014 at 09:01 PM.
Reason: Included changelog notes for Pidgin 2.10.8 related to XMMP
I usually don't reply to old posts, but as this is stickied I assume that the no-necromancy rule does not apply...
I recently went lifetime and was interested in this feature. After some minor difficulties I was able to connect with Pidgin on my PC, but neither of the Android clients I tried would connect.
Anybody out there know of an Android client that works currently? Both the ones I tried were mentioned in the thread earlier as working but then as we near the end of the thread I see many people with newer problems. Just curious if anybody could recommend a client that is known to currently work, as to make my trouble shooting go a bit easier.
I once again match my character. Behold the power of PINK!