Gaim: MSN protocol parsing function buffer overflow
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200408-12 / gaim |
| Release Date |
August 12, 2004 |
| Latest Revision |
May 22, 2006: 03 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-im/gaim |
<=
0.81 |
>=
0.81-r1 |
All supported architectures
|
Related bugreports:
#60034
Synopsis
Gaim contains a remotely exploitable buffer overflow vulnerability in the
MSN-protocol parsing code that may allow remote execution of arbitrary
code.
2.
Impact Information
Background
Gaim is a multi-protocol instant messaging client for Linux which
supports many instant messaging protocols.
Description
Sebastian Krahmer of the SuSE Security Team has discovered a remotely
exploitable buffer overflow vulnerability in the code handling MSN
protocol parsing.
Impact
By sending a carefully-crafted message, an attacker may execute
arbitrary code with the permissions of the user running Gaim.
3.
Resolution Information
Workaround
There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version of Gaim.
Resolution
All Gaim users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge sync
# emerge -pv ">=net-im/gaim-0.81-r1"
# emerge ">=net-im/gaim-0.81-r1"
|
4.
References
|