GNU Gadu, CenterICQ, Kadu, EKG, libgadu: Remote code execution in Gadu library
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200507-26 / gnugadu centericq kadu ekg libgadu |
| Release Date |
July 27, 2005 |
| Latest Revision |
February 26, 2007: 02 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-im/gnugadu |
<
2.2.6-r1 |
>=
2.2.6-r1 |
All supported architectures
|
| net-im/centericq |
<
4.20.0-r3 |
>=
4.20.0-r3 |
All supported architectures
|
| net-im/kadu |
<
0.4.1 |
>=
0.4.1 |
All supported architectures
|
| net-im/ekg |
<
1.6_rc3 |
>=
1.6_rc3 |
All supported architectures
|
| net-libs/libgadu |
<
1.7.0_pre20050719 |
>=
1.7.0_pre20050719 |
All supported architectures
|
Related bugreports:
#99816, #99890, #99583
Synopsis
GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow which could potentially lead to the execution of arbitrary code or
a Denial of Service.
2.
Impact Information
Background
GNU Gadu, CenterICQ, Kadu and EKG are instant messaging applications
created to support Gadu Gadu instant messaging protocol. libgadu is a
library that implements the client side of the Gadu-Gadu protocol.
Description
GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow.
Impact
A remote attacker could exploit the integer overflow to execute
arbitrary code or cause a Denial of Service.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All GNU Gadu users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/gnugadu-2.2.6-r1"
|
All Kadu users should upgrade to the latest version:
Code Listing 3.2: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/kadu-0.4.1"
|
All EKG users should upgrade to the latest version:
Code Listing 3.3: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/ekg-1.6_rc3"
|
All libgadu users should upgrade to the latest version:
Code Listing 3.4: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-20050719"
|
All CenterICQ users should upgrade to the latest version:
Code Listing 3.5: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/centericq-4.20.0-r3"
|
CenterICQ is no longer distributed with Gadu Gadu support, affected
users are encouraged to migrate to an alternative package.
4.
References
|