IceTalk.com    Add links ...   Not registered? Get a free account 
gnu gadu centericq kadu ekg libgad
   
Name:   Pass:  
 Free NewsLetter
 



 
Homepage
News
Security
Press Releases
Software
Community
Education
Jobs


  
 
  All News  |  Submit News  |  Login  |  About / Contact  |  NewsLetter  |
 Software    

Gentoo Linux Security Advisory: GNU Gadu, CenterICQ, Kadu, EKG, libgad

Wednesday, July 27th 10:00:20
--nextPart1627487.rMtabyJHyG
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200507-26
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: GNU Gadu, CenterICQ, Kadu, EKG, libgadu: Remote code
execution in Gadu library
Date: July 27, 2005
Bugs: #99816, #99890, #99583
ID: 200507-26

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow which could potentially lead to the execution of arbitrary
code or a Denial of Service.

Background
==========

GNU Gadu, CenterICQ, Kadu and EKG are instant messaging applications
created to support Gadu Gadu instant messaging protocol. libgadu is a
library that implements the client side of the Gadu-Gadu protocol.

Affected packages
=================

-------------------------------------------------------------------
Package           /   Vulnerable   /                   Unaffected
-------------------------------------------------------------------
1  net-im/gnugadu        < 2.2.6-r1                      >= 2.2.6-r1
2  net-im/centericq      < 4.20.0-r3                    >= 4.20.0-r3
3  net-im/kadu             < 0.4.1                          >= 0.4.1
4  net-im/ekg             < 1.6_rc3                       >= 1.6_rc3
5  net-libs/libgadu      < 20050719                      >= 20050719
-------------------------------------------------------------------
5 affected packages on all of their supported architectures.
-------------------------------------------------------------------

Description
===========

GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow.

Impact
======

A remote attacker could exploit the integer overflow to execute
arbitrary code or cause a Denial of Service.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All GNU Gadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/gnugadu-2.2.6-r1"

All Kadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/kadu-0.4.1"

All EKG users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/ekg-1.6_rc3"

All libgadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-20050719"

All CenterICQ users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/centericq-4.20.0-r3"

CenterICQ is no longer distributed with Gadu Gadu support, affected
users are encouraged to migrate to an alternative package.

References
==========

[ 1 ] CAN-2005-1852
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1852
[ 2 ] BugTraq Announcement
http://www.securityfocus.com/archive/1/406026/30/

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200507-26.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
 or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2005 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

--nextPart1627487.rMtabyJHyG
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQBC5zCkzKC5hMHO6rkRAuooAJ4096EgTKHSFD5LplqVXVI3IF/1uACfaWvs
AQ05FxqMoKdtYG7QFqa1r40=
=P4s2
-----END PGP SIGNATURE-----
--nextPart1627487.rMtabyJHyG
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200507-26
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: GNU Gadu, CenterICQ, Kadu, EKG, libgadu: Remote code
execution in Gadu library
Date: July 27, 2005
Bugs: #99816, #99890, #99583
ID: 200507-26

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis


GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow which could potentially lead to the execution of arbitrary
code or a Denial of Service.

Background
==========

GNU Gadu, CenterICQ, Kadu and EKG are instant messaging applications
created to support Gadu Gadu instant messaging protocol. libgadu is a
library that implements the client side of the Gadu-Gadu protocol.

Affected packages
=================

-------------------------------------------------------------------
Package           /   Vulnerable   /                   Unaffected
-------------------------------------------------------------------
1  net-im/gnugadu        < 2.2.6-r1                      >= 2.2.6-r1
2  net-im/centericq      < 4.20.0-r3                    >= 4.20.0-r3
3  net-im/kadu             < 0.4.1                          >= 0.4.1
4  net-im/ekg             < 1.6_rc3                       >= 1.6_rc3
5  net-libs/libgadu      < 20050719                      >= 20050719
-------------------------------------------------------------------
5 affected packages on all of their supported architectures.
-------------------------------------------------------------------

Description
===========

GNU Gadu, CenterICQ, Kadu, EKG and libgadu are vulnerable to an integer
overflow.

Impact
======

A remote attacker could exploit the integer overflow to execute
arbitrary code or cause a Denial of Service.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All GNU Gadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/gnugadu-2.2.6-r1"

All Kadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/kadu-0.4.1"

All EKG users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/ekg-1.6_rc3"

All libgadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-20050719"

All CenterICQ users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/centericq-4.20.0-r3"

CenterICQ is no longer distributed with Gadu Gadu support, affected
users are encouraged to migrate to an alternative package.

References
==========

[ 1 ] CAN-2005-1852
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1852
[ 2 ] BugTraq Announcement
http://www.securityfocus.com/archive/1/406026/30/

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200507-26.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
 or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2005 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0

--nextPart1627487.rMtabyJHyG
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQBC5zCkzKC5hMHO6rkRAuooAJ4096EgTKHSFD5LplqVXVI3IF/1uACfaWvs
AQ05FxqMoKdtYG7QFqa1r40=
=P4s2
-----END PGP SIGNATURE-----

--nextPart1627487.rMtabyJHyG--
--
 mailing list



Previous stories in 'Software' :
latest software releases from icewalkers.com
latest software releases from icewalkers.com
latest software releases from icewalkers.com
latest software releases from icewalkers.com
latest software releases from icewalkers.com
latest software releases from icewalkers.com
latest software releases from icewalkers.com



 No Comment yet.  
 
 Last News
 
Saturday, February 16th

Slackware Advisory: Apache (SSA:2008-045-02)

Slackware Advisory: Php (SSA:2008-045-03)

Slackware Advisory: Httpd (SSA:2008-045-01)

Gentoo Linux Security Advisory: Boost

FreeBSD Security Advisory: ipsec

FreeBSD Security Advisory: sys_kern

Gentoo Linux Security Advisory: Pulseaudio

Slackware Advisory: Firefox, seamonkey (SSA:2008-043-01)

Slackware Advisory: Kernel exploit fix (SSA:2008-042-01)

Gentoo Linux Security Advisory: Scponly

Gentoo Linux Security Advisory: Gnumeric

Gentoo Linux Security Advisory: Gallery

Gentoo Linux Security Advisory: Horde IMP


 

 
  All News  |  Submit News  |  Login  |  About / Contact  |  NewsLetter  |
 
.Copyright 2010 IceTalk.com - All Rights Reserved.   Privacy Policy