Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200408-27 ] Gaim: New vulnerabilities
Date: Fri, 27 Aug 2004 19:03:55
Message-Id: 200408272053.01292.jaervosz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200408-27
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Gaim: New vulnerabilities
12 Date: August 27, 2004
13 Bugs: #61457
14 ID: 200408-27
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Gaim contains several security issues that might allow an attacker to
22 execute arbitrary code or commands.
23
24 Background
25 ==========
26
27 Gaim is a multi-protocol instant messaging client for Linux which
28 supports many instant messaging protocols.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 net-im/gaim < 0.81-r5 >= 0.81-r5
37
38 Description
39 ===========
40
41 Gaim fails to do proper bounds checking when:
42
43 * Handling MSN messages (partially fixed with GLSA 200408-12).
44
45 * Handling rich text format messages.
46
47 * Resolving local hostname.
48
49 * Receiving long URLs.
50
51 * Handling groupware messages.
52
53 * Allocating memory for webpages with fake content-length header.
54
55 Furthermore Gaim fails to escape filenames when using drag and drop
56 installation of smiley themes.
57
58 Impact
59 ======
60
61 These vulnerabilites could allow an attacker to crash Gaim or execute
62 arbitrary code or commands with the permissions of the user running
63 Gaim.
64
65 Workaround
66 ==========
67
68 There is no known workaround at this time. All users are encouraged to
69 upgrade to the latest available version of Gaim.
70
71 Resolution
72 ==========
73
74 All gaim users should upgrade to the latest version:
75
76 # emerge sync
77
78 # emerge -pv ">=net-im/gaim-0.81-r5"
79 # emerge ">=net-im/gaim-0.81-r5"
80
81 References
82 ==========
83
84 [ 1 ] Gaim security issues
85 http://gaim.sourceforge.net/security/index.php
86
87 Availability
88 ============
89
90 This GLSA and any updates to it are available for viewing at
91 the Gentoo Security Website:
92
93 http://security.gentoo.org/glsa/glsa-200408-27.xml
94
95 Concerns?
96 =========
97
98 Security is a primary focus of Gentoo Linux and ensuring the
99 confidentiality and security of our users machines is of utmost
100 importance to us. Any security concerns should be addressed to
101 security@g.o or alternatively, you may file a bug at
102 http://bugs.gentoo.org.
103
104 License
105 =======
106
107 Copyright 2004 Gentoo Foundation, Inc; referenced text
108 belongs to its owner(s).
109
110 The contents of this document are licensed under the
111 Creative Commons - Attribution / Share Alike license.
112
113 http://creativecommons.org/licenses/by-sa/1.0
114 -----BEGIN PGP SIGNATURE-----
115 Version: GnuPG v1.2.4 (GNU/Linux)
116
117 iD8DBQFBL4L7zKC5hMHO6rkRAiTcAJ9qjmLs0yaTCLN2WvTv59oVJwDTagCgjJdC
118 fgR31dIfTwjGmgwD6PFQ8bk=
119 =TkqR
120 -----END PGP SIGNATURE-----