Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 102000
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jean-François Brunette (RETIRED) <formula7@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 102000 depends on: Show dependency tree
Bug 102000 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-08-10 09:08 0000
CVE reference: CAN-2005-2102
CAN-2005-2103
 
 
Description:
A vulnerability and a weakness have been reported in Gaim, which can be 
exploited by malicious people to cause a DoS (Denial of Service) or compromise 
a user's system.

1) An error in the handling of away messages can be exploited to cause a heap-
based buffer overflow by sending a specially crafted away message to a user 
logged into AIM or ICQ.

Successful exploitation allows execution of arbitrary code.

2) An error in the handling of file transfers can be exploited to crash the 
application by attempting to upload a file with a non-UTF8 filename to a user 
logged into AIM or ICQ. 

----------------------

All versions seem to be vulnerable.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-08-10 10:22:41 0000 -------
Pulling in net-im herd so that they are ready whenever upstream is.

------- Comment #2 From Don Seiler (RETIRED) 2005-08-10 10:40:40 0000 -------
gaim-1.5.0 slated for release Thurs evening.

------- Comment #3 From Sebastian 2005-08-11 09:33:14 0000 -------
*** Bug 102133 has been marked as a duplicate of this bug. ***

------- Comment #4 From Robert Paskowitz (RETIRED) 2005-08-11 21:23:41 0000 -------
1.5.0 is also fixing CAN-2005-2370:

Summary:A memory alignment bug in the Gadu-Gadu protocol plugin can result in a buffer overflow
Description: There was a memory alignment bug in the library Gaim uses to access the Gadu-Gadu 
network. This bug can not be exploited on x86 architectures. This bug was recently fixed in the libgadu 
library, but also needed to be fixed in Gaim because Gaim includes a copy of the libgadu library.

------- Comment #5 From Don Seiler (RETIRED) 2005-08-11 21:38:40 0000 -------
Memory alignment bug was fixed in 1.4.0-r2.

I currently don't have a viable gentoo desktop, thanks to some CPU/mobo frying.
 tester@gentoo.org is going to cover this for me.

------- Comment #6 From Olivier Crete 2005-08-11 21:43:46 0000 -------
added gaim-1.5.0 and marked it stable for x86 & amd64

------- Comment #7 From Stefan Cornelius (RETIRED) 2005-08-11 21:51:18 0000 -------
Arches please test and mark gaim-1.5.0 stable, thanks

------- Comment #8 From Jory A. Pratt 2005-08-11 22:12:06 0000 -------
Stable on PPC.

------- Comment #9 From Markus Rothe 2005-08-12 00:37:36 0000 -------
stable on ppc64

------- Comment #10 From Gustavo Zacarias (RETIRED) 2005-08-12 07:07:36 0000 -------
sparc stable.

------- Comment #11 From Fernando J. Pereda (RETIRED) 2005-08-12 07:59:24 0000 -------
alpha stable

------- Comment #12 From Aaron Walker (RETIRED) 2005-08-12 09:02:29 0000 -------
stable on mips.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-08-12 13:46:58 0000 -------
It still misses hppa.

------- Comment #14 From Bryan Østergaard (RETIRED) 2005-08-12 15:02:24 0000 -------
Stable on ia64.

------- Comment #15 From Michael Hanselmann (hansmi) (RETIRED) 2005-08-13 00:25:03 0000 -------
Stable on hppa.

------- Comment #16 From Sune Kloppenborg Jeppesen 2005-08-14 22:32:58 0000 -------
GLSA 200508-06 
 
arm please remember to mark stable to benifit from the GLSA. 

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug