Not logged in
Log in now
Create an account
Subscribe to LWN
Recent Features
LWN.net Weekly Edition for February 9, 2012
XBMC 11 "Eden"
LWN.net Weekly Edition for February 2, 2012
A tempest in a toybox
LWN.net Weekly Edition for January 26, 2012
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : gaim SUMMARY : Fixes for gaim's vulnerabilities DATE : 2005-03-14 11:55:00 ID : CLA-2005:933 RELEVANT RELEASES : 9, 10 - ------------------------------------------------------------------------- DESCRIPTION Gaim[1] is a multi-protocol instant messaging (IM) client. This announcement fixes three denial of service vulnerabilities that were encountered in Gaim. The fixed vulnerabilities are: CAN-2005-0472[2]: Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from AIM or ICQ. CAN-2005-0473[3]: The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes an invalid memory access. CAN-2005-0208[4]: The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes an invalid memory access. This vulnerabity is diferent from CAN-2005-0473. For further informations on Gaim's vulnerabilities, please refer to the project's security page[5]. SOLUTION It is recommended that all Gaim users upgrade their packages. IMPORTANT: Gaim must be restarted after the upgrade in order to close the vulnerabilities. REFERENCES 1.http://gaim.sourceforge.net/ 2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0472 3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0473 4.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0208 5.http://gaim.sourceforge.net/security/ UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/10/SRPMS/gaim-1.1.4-6... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-1.1.4-69... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-am-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-bg-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ca-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-cs-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-da-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-de-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-es-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-fi-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-fr-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-he-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-hi-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-hu-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-it-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ja-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ko-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-lt-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-mk-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-my_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-nl-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-no-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pl-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pt-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pt_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ro-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ru-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sk-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sl-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sq-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sr-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sv-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-tr-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-uk-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-vi-... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-zh_... ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-zh_... ftp://atualizacoes.conectiva.com.br/10/RPMS/libgaim-remot... ftp://atualizacoes.conectiva.com.br/10/RPMS/libgaim-remot... ftp://atualizacoes.conectiva.com.br/9/SRPMS/gaim-1.1.4-27... ftp://atualizacoes.conectiva.com.br/9/RPMS/gaim-1.1.4-276... ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFCNaZa42jd0JmAcZARAvvgAKC9WyDa9lDSYcHLRdxSWmE/DXGG5wCgokWF qeboeGlHck9Owze73If0Alo= =snRb -----END PGP SIGNATURE-----
Copyright © 2012, Eklektix, Inc. Comments and public postings are copyrighted by their creators. Linux is a registered trademark of Linus Torvalds