[Full-Disclosure] [USN-85-1] Gaim vulnerabilities

From: Martin Pitt (martin.pitt_at_canonical.com)
Date: 02/25/05

  • Next message: bkfsec: "Re: [Full-Disclosure] Xfree86 video buffering?"
    Date: Fri, 25 Feb 2005 17:00:44 +0100
    To: ubuntu-security-announce@lists.ubuntu.com
    
    
    
    

    ===========================================================
    Ubuntu Security Notice USN-85-1 February 25, 2005
    gaim vulnerabilities
    CAN-2005-0208, CAN-2005-0472, CAN-2005-0473
    ===========================================================

    A security issue affects the following Ubuntu releases:

    Ubuntu 4.10 (Warty Warthog)

    The following packages are affected:

    gaim

    The problem can be corrected by upgrading the affected package to
    version 1:1.0.0-1ubuntu1.2. In general, a standard system upgrade is
    sufficient to effect the necessary changes.

    Details follow:

    The Gaim developers discovered that the HTML parser did not
    sufficiently validate its input. This allowed a remote attacker to
    crash the Gaim client by sending certain malformed HTML messages.
    (CAN-2005-0208, CAN-2005-0473)

    Another lack of sufficient input validation was found in the "Oscar"
    protocol handler which is used for ICQ and AIM. By sending specially
    crafted packets, remote users could trigger an infinite loop in Gaim
    which caused Gaim to become unresponsive and hang. (CAN-2005-0472)

      Source archives:

        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1.2.diff.gz
          Size/MD5: 42432 088aa80f79950d5efa7f6afc29d2915e
        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1.2.dsc
          Size/MD5: 853 66848ad2c5b6ef2c136e8419d9c84e72
        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0.orig.tar.gz
          Size/MD5: 6985979 7dde686aace751a49dce734fd0cb7ace

      amd64 architecture (Athlon64, Opteron, EM64T Xeon)

        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1.2_amd64.deb
          Size/MD5: 3444018 f829005df6031fa36622e04bcb30968e

      i386 architecture (x86 compatible Intel/AMD)

        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1.2_i386.deb
          Size/MD5: 3354146 f85b4b98fc5bc04fe494a5303f225967

      powerpc architecture (Apple Macintosh G3/G4/G5)

        http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1.2_powerpc.deb
          Size/MD5: 3417968 614a7816b433efb292944822479661b1

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: bkfsec: "Re: [Full-Disclosure] Xfree86 video buffering?"

    Relevant Pages

    • [Full-disclosure] [USN-125-1] Gaim vulnerabilities
      ... gaim vulnerabilities ... Ubuntu 4.10 ... Updated packages for Ubuntu 4.10: ... amd64 architecture ...
      (Full-Disclosure)
    • [Full-disclosure] [USN-140-1] Gaim vulnerability
      ... gaim vulnerability ... Ubuntu 4.10 ... Updated packages for Ubuntu 4.10: ... amd64 architecture ...
      (Full-Disclosure)
    • [Full-disclosure] [USN-140-1] Gaim vulnerability
      ... gaim vulnerability ... Ubuntu 4.10 ... Updated packages for Ubuntu 4.10: ... amd64 architecture ...
      (Full-Disclosure)
    • [USN-168-1] Gaim vulnerabilities
      ... gaim vulnerabilities ... Ubuntu 4.10 ... Updated packages for Ubuntu 4.10: ... amd64 architecture ...
      (Bugtraq)
    • Re: GAIM 1.5.0
      ... run apt-get dist-upgrade it tells me that it wants to update GAIM when the ... Is there any way I can continue upgrading everything else EXCEPT ... could also stop other packages from being upgraded due to dependencies. ... his/her work into debian by having a debian-developers look at it and ok ...
      (Debian-User)