[CLA-2005:933] Conectiva Security Announcement - gaim

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 03/14/05

  • Next message: Sebastian Krahmer: "SUSE Security Announcement: openslp (SUSE-SA:2005:015)"
    Date: Mon, 14 Mar 2005 11:57:31 -0300
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : gaim
    SUMMARY : Fixes for gaim's vulnerabilities
    DATE : 2005-03-14 11:55:00
    ID : CLA-2005:933
    RELEVANT
    RELEASES : 9, 10

    - -------------------------------------------------------------------------

    DESCRIPTION
     Gaim[1] is a multi-protocol instant messaging (IM) client.
     
     This announcement fixes three denial of service vulnerabilities that
     were encountered in Gaim.
     
     The fixed vulnerabilities are:
     
     CAN-2005-0472[2]: Gaim before 1.1.3 allows remote attackers to cause
     a denial of service (infinite loop) via malformed SNAC packets from
     AIM or ICQ.
     
     CAN-2005-0473[3]: The HTML parsing functions in Gaim before 1.1.3
     allow remote attackers to cause a denial of service (application
     crash) via malformed HTML that causes an invalid memory access.
     
     CAN-2005-0208[4]: The HTML parsing functions in Gaim before 1.1.4
     allow remote attackers to cause a denial of service (application
     crash) via malformed HTML that causes an invalid memory access. This
     vulnerabity is diferent from CAN-2005-0473.
     
     For further informations on Gaim's vulnerabilities, please refer to
     the project's security page[5].

    SOLUTION
     It is recommended that all Gaim users upgrade their packages.
     
     IMPORTANT: Gaim must be restarted after the upgrade in order to close
     the vulnerabilities.
     
     
     REFERENCES
     1.http://gaim.sourceforge.net/
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0472
     3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0473
     4.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0208
     5.http://gaim.sourceforge.net/security/

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/10/SRPMS/gaim-1.1.4-69982U10_2cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-am-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-bg-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ca-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-cs-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-da-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-de-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_AU-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_CA-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-en_GB-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-es-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-fi-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-fr-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-he-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-hi-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-hu-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-it-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ja-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ko-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-lt-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-mk-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-my_MM-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-nl-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-no-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pl-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pt-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-pt_BR-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ro-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-ru-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sk-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sl-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sq-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sr-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-sv-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-tr-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-uk-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-vi-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-zh_CN-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/gaim-i18n-zh_TW-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/libgaim-remote-devel-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/10/RPMS/libgaim-remote0-1.1.4-69982U10_2cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/gaim-1.1.4-27683U90_3cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/gaim-1.1.4-27683U90_3cl.i386.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions regarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2004 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQFCNaZa42jd0JmAcZARAvvgAKC9WyDa9lDSYcHLRdxSWmE/DXGG5wCgokWF
    qeboeGlHck9Owze73If0Alo=
    =snRb
    -----END PGP SIGNATURE-----


  • Next message: Sebastian Krahmer: "SUSE Security Announcement: openslp (SUSE-SA:2005:015)"

    Relevant Pages

    • [CLA-2004:821] Conectiva Security Announcement - XFree86
      ... Greg MacManus from iDEFENSE Labs discoveredtwo vulnerabilities ... in the way the X server deals with font files. ... It is recommended that all XFree86 users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2004:866] Conectiva Security Announcement - qt3
      ... Fixes for image loader vulnerabilities ... It is recommended that all qt users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:662] Conectiva Security Announcement - ethereal
      ... These vulnerabilities can be exploited ... All ethereal users should upgrade their packages. ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2003:738] Conectiva Security Announcement - pine
      ... Pine is a mail and news text based client developed by the Washington ... This update fixes two pine remote vulnerabilities found by ... The apt tool can be used to perform RPM packages upgrades: ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)
    • [CLA-2005:949] Conectiva Security Announcement - gaim
      ... SUMMARY: Fixes for gaim's vulnerabilities ... were encountered in Gaim. ... It is recommended that all Gaim users upgrade their packages. ... Detailed instructions regarding the use of apt and upgrade examples ...
      (Bugtraq)