Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 99690 - net-im/kadu-0.4.0 - possible remote execution of arbitrary code
Summary: net-im/kadu-0.4.0 - possible remote execution of arbitrary code
Status: RESOLVED DUPLICATE of bug 99583
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: x86 Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.kadu.net/download/stable/k...
Whiteboard: B1 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-20 09:15 UTC by tomek@paradox.pl
Modified: 2005-07-20 14:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description tomek@paradox.pl 2005-07-20 09:15:12 UTC
Kadu 0.4.1 (stable release)
- solved critical security bug
- solved one memory leak
- two new modules
- stabilized voice conversations

Reproducible: Always
Steps to Reproduce:
none
Comment 1 tomek@paradox.pl 2005-07-20 09:18:20 UTC
Kadu 0.4.1:
http://www.kadu.net/download/stable/kadu-0.4.1.tar.bz2
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2005-07-20 09:27:45 UTC
http://www.kadu.net/index.php?page=news&lang=en

<snip>
Kadu 0.4.1 has been released. It is solely a bugfix release, so new
functionality should not be expected (apart from one exception, read on). We
fixed a couple of memory leaks, voice chat is more stable, a couple modules were
added to the auto download mechanism. But this release carries two important
changes as well. 

One is a fix of a severe security vulnerability in libgadu (the library
responsible for communicating with the server). Exploitation of this bug can
lead to an abnormal termination of the application (this applies to all libgadu
based programs) and possibly remote execution of ANY ARBITRARY code - we highly
recommend to update!
</snip>
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2005-07-20 09:42:17 UTC
According to bug #99583 net-im is already working on new ebuilds.
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2005-07-20 14:12:26 UTC
No further need for this bug, reopen if you disagree.

*** This bug has been marked as a duplicate of 99583 ***