Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] [ GLSA 200408-27 ] Gaim: New vulnerabilities |
|---|---|
| Date: | Fri, 27 Aug 2004 20:52:43 +0200 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200408-27
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Gaim: New vulnerabilities
Date: August 27, 2004
Bugs: #61457
ID: 200408-27
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Gaim contains several security issues that might allow an attacker to
execute arbitrary code or commands.
Background
==========
Gaim is a multi-protocol instant messaging client for Linux which
supports many instant messaging protocols.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-im/gaim < 0.81-r5 >= 0.81-r5
Description
===========
Gaim fails to do proper bounds checking when:
* Handling MSN messages (partially fixed with GLSA 200408-12).
* Handling rich text format messages.
* Resolving local hostname.
* Receiving long URLs.
* Handling groupware messages.
* Allocating memory for webpages with fake content-length header.
Furthermore Gaim fails to escape filenames when using drag and drop
installation of smiley themes.
Impact
======
These vulnerabilites could allow an attacker to crash Gaim or execute
arbitrary code or commands with the permissions of the user running
Gaim.
Workaround
==========
There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version of Gaim.
Resolution
==========
All gaim users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-im/gaim-0.81-r5"
# emerge ">=net-im/gaim-0.81-r5"
References
==========
[ 1 ] Gaim security issues
http://gaim.sourceforge.net/security/index.php
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200408-27.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2004 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/1.0
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBL4L7zKC5hMHO6rkRAiTcAJ9qjmLs0yaTCLN2WvTv59oVJwDTagCgjJdC
fgR31dIfTwjGmgwD6PFQ8bk=
=TkqR
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] [ GLSA 200408-26 ] zlib: Denial of service vulnerability, Sune Kloppenborg Jeppesen |
|---|---|
| Next by Date: | Alpha Phising [IE 6 WinXP SP2], mikx |
| Previous by Thread: | [Full-Disclosure] [ GLSA 200408-26 ] zlib: Denial of service vulnerability, Sune Kloppenborg Jeppesen |
| Next by Thread: | Alpha Phising [IE 6 WinXP SP2], mikx |
| Indexes: | [Date] [Thread] [Top] [All Lists] |