Gentoo Archives: gentoo-announce

From: Luke Macken <lewk@g.o>
To: gentoo-announce@××××××××××××.org
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200504-05 ] Gaim: Denial of Service issues
Date: Wed, 06 Apr 2005 12:21:03
Message-Id: 20050406122100.GA23961@tomservo.hsd1.ma.comcast.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200504-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Gaim: Denial of Service issues
9 Date: April 06, 2005
10 Updated: April 06, 2005
11 Bugs: #87903
12 ID: 200504-05:02
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 Gaim contains multiple vulnerabilities that can lead to a Denial of
20 Service.
21
22 Background
23 ==========
24
25 Gaim is a full featured instant messaging client which handles a
26 variety of instant messaging protocols.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-im/gaim < 1.2.1 >= 1.2.1
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been addressed in the latest release of
40 Gaim:
41
42 * A buffer overread in the gaim_markup_strip_html() function, which
43 is used when logging conversations (CAN-2005-0965).
44
45 * Markup tags are improperly escaped using Gaim's IRC plugin
46 (CAN-2005-0966).
47
48 * Sending a specially crafted file transfer request to a Gaim Jabber
49 user can trigger a crash (CAN-2005-0967).
50
51 Impact
52 ======
53
54 An attacker could possibly cause a Denial of Service by exploiting any
55 of these vulnerabilities.
56
57 Workaround
58 ==========
59
60 There is no known workaround at this time.
61
62 Resolution
63 ==========
64
65 All Gaim users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot --verbose ">=net-im/gaim-1.2.1"
69
70 References
71 ==========
72
73 [ 1 ] CAN-2005-0967
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0967
75 [ 2 ] CAN-2005-0966
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0966
77 [ 3 ] CAN-2005-0965
78 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0965
79 [ 4 ] Gaim Vulnerability Index
80 http://gaim.sourceforge.net/security/
81
82 Availability
83 ============
84
85 This GLSA and any updates to it are available for viewing at
86 the Gentoo Security Website:
87
88 http://security.gentoo.org/glsa/glsa-200504-05.xml
89
90 Concerns?
91 =========
92
93 Security is a primary focus of Gentoo Linux and ensuring the
94 confidentiality and security of our users machines is of utmost
95 importance to us. Any security concerns should be addressed to
96 security@g.o or alternatively, you may file a bug at
97 http://bugs.gentoo.org.
98
99 License
100 =======
101
102 Copyright 2005 Gentoo Foundation, Inc; referenced text
103 belongs to its owner(s).
104
105 The contents of this document are licensed under the
106 Creative Commons - Attribution / Share Alike license.
107
108 http://creativecommons.org/licenses/by-sa/2.0