SILC: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201006-07 / silc-toolkit silc-client |
| Release Date |
June 01, 2010 |
| Latest Revision |
June 01, 2010: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-im/silc-toolkit |
<
1.1.10 |
>=
1.1.10 |
All supported architectures
|
| net-im/silc-client |
<
1.1.8 |
>=
1.1.8 |
All supported architectures
|
Related bugreports:
#284561
Synopsis
Multiple vulnerabilities were discovered in SILC Toolkit and SILC Client,
the worst of which allowing for execution of arbitrary code.
2.
Impact Information
Background
SILC (Secure Internet Live Conferencing protocol) Toolkit is a software
development kit for use in clients, and SILC Client is an IRSSI-based
text client.
Description
Multiple vulnerabilities were discovered in SILC Toolkit and SILC
Client. For further information please consult the CVE entries
referenced below.
Impact
A remote attacker could overwrite stack locations and possibly execute
arbitrary code via a crafted OID value, Content-Length header or format
string specifiers in a nickname field or channel name.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All SILC Toolkit users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/silc-toolkit-1.1.10"
|
All SILC Client users should upgrade to the latest version:
Code Listing 3.2: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/silc-client-1.1.8"
|
4.
References
|