Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Multiple vulnerabilities in libgadu and ekg package |
|---|---|
| Date: | Thu, 21 Jul 2005 20:58:55 +0200 |
Bugs fixed in ekg-1.6rc3:
- integer overflow in libgadu (CAN-2005-1852) that could be triggered by an incomming message and lead to application crash and/or remote code execution (discovered by Marcin Ślusarz),
Bugs fixed in ekg-1.6rc2:
- insecure file creation in user contributed Python script (CAN-2005-1916, discovered by Eric Romang of ZATAZ audit),
- insecure file creation (CAN-2005-1850) and shell command injection (CAN-2005-1851) in other user contributed scripts (discovered by Marcin Owsiany and Wojtek Kaniewski),
- several signedness errors in libgadu that could be triggered by an incomming network data or an application passing invalid user input to the library (discovered by Grzegorz Jaśkiewicz),
- memory alignment errors in libgadu that could be triggered by an incomming message and lead to bus errors on architectures like SPARC (discovered by Szymon Zygmunt and Michał Bartoszkiewicz),
- endianness errors in libgadu that could cause invalid behaviour of applications on big-endian architectures (discovered by Marcin Ślusarz).
http://dev.null.pl/ekg/ekg-1.6rc3.tar.gz
Regards, Wojtek Kaniewski
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Peter Gutmann data deletion theaory?, Glenn.Everhart |
|---|---|
| Next by Date: | RE: Peter Gutmann data deletion theaory?, Barbara Lockwood |
| Previous by Thread: | MDKSA-2005:122 - Updated kdelibs packages fix vulnerability in kate and kwrite, Mandriva Security Team |
| Next by Thread: | Mozilla XPCOM Library Race Condition, GulfTech Security Research |
| Indexes: | [Date] [Thread] [Top] [All Lists] |