LWN.net Logo

gajim: multiple vulnerabilities

Package(s):gajim CVE #(s):CVE-2012-1987 CVE-2012-2093 CVE-2012-2086 CVE-2012-2085
Created:April 16, 2012 Updated:August 15, 2012
Description: From the Debian advisory:

CVE-2012-1987: gajim is not properly sanitizing input before passing it to shell commands. An attacker can use this flaw to execute arbitrary code on behalf of the victim if the user e.g. clicks on a specially crafted URL in an instant message.

CVE-2012-2093: gajim is using predictable temporary files in an insecure manner when converting instant messages containing LaTeX to images. A local attacker can use this flaw to conduct symlink attacks and overwrite files the victim has write access to.

CVE-2012-2086: gajim is not properly sanitizing input when logging conversations which results in the possibility to conduct SQL injection attacks.

CVE-2012-2085: unspecified

Alerts:
Debian DSA-2453-1 2012-04-16
Debian DSA-2453-2 2012-04-19
Fedora FEDORA-2012-6061 2012-04-27
Fedora FEDORA-2012-6001 2012-04-27
Mageia MGASA-2012-0161 2012-07-13
Gentoo 201208-04 2012-08-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds