SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Instant Messaging/IRC/Chat)  >   Gaim Vendors:   Gaim.sourceforge.net
(Mandrake Issues Fix) Gaim Buffer Overflows in Groupware Messages, URLs, Hostname Lookups, and RTF Messages May Permit Remote Code Execution
SecurityTracker Alert ID:  1011876
SecurityTracker URL:  http://securitytracker.com/id/1011876
CVE Reference:   CAN-2004-0785, CAN-2004-0754   (Links to External Site)
Date:  Oct 21 2004
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 0.82
Description:   Several overflow vulnerabilities were reported in Gaim. A remote user may be able to execute arbitrary code on the target system. A remote server can also cause the Gaim client to crash.

The vendor reported that a remote groupware server can send specially crafted messages to a target client to trigger a memory allocation integer overflow [CVE: CAN-2004-0754]. The resulting heap overflow may allow arbitrary code to be executed.

It is also reported that a remote user can send a specially crafted URL that, when received by the target user, will overflow a static buffer of 2048 bytes [CVE: CAN-2004-0785].

It is also reported that a hostname lookup overflow can be triggered [CVE: CAN-2004-0785]. If the DNS server returns a hostname that is greater than MAXHOSTNAMELEN bytes, a buffer overflow will occur.

It is also reported that a remote user can create an invalid rich text format (RTF) message to trigger one of several buffer overflows [CVE: CAN-2004-0785].

It is also reported that a remote web server can return a large HTTP Content-Length header value to cause the target user's Gaim to crash. This can be triggered if the supplied length value is large enough to cause Gaim to consume all available memory. This can occur when Gaim reads profile information on some protocols and when smiley themes are installed via drag and drop.

The original advisories are available at:

http://gaim.sourceforge.net/security/index.php?id=2
http://gaim.sourceforge.net/security/index.php?id=3
http://gaim.sourceforge.net/security/index.php?id=4
http://gaim.sourceforge.net/security/index.php?id=5
http://gaim.sourceforge.net/security/index.php?id=6

Impact:   A remote user can cause arbitrary code to be executed on the target application or cause the application to crash.
Solution:   Mandrake has released a fix.

Mandrakelinux 10.0:
fb5e0402f4debc556bbd9415d96f9638 10.0/RPMS/gaim-0.75-5.3.100mdk.i586.rpm
9b398cc925dabbf3cdc5f2dd412d09cb 10.0/RPMS/gaim-encrypt-0.75-5.3.100mdk.i586.rpm
d27addd1e3d0392f1076cb26ff274af3 10.0/RPMS/gaim-festival-0.75-5.3.100mdk.i586.rpm
2076ce789cfd20e8a09963d7966846d6 10.0/RPMS/gaim-perl-0.75-5.3.100mdk.i586.rpm
e9bb68490f6e66f8f53602c646bfe6e8 10.0/RPMS/libgaim-remote0-0.75-5.3.100mdk.i586.rpm
1fc1fb4b90b3772b315b84c35c9a91c1 10.0/RPMS/libgaim-remote0-devel-0.75-5.3.100mdk.i586.rpm
949b9d4232202401c724cb01fc220e1e 10.0/SRPMS/gaim-0.75-5.3.100mdk.src.rpm

Mandrakelinux 10.0/AMD64:
63f64fdf9a464f06a6626b27ca7a523c amd64/10.0/RPMS/gaim-0.75-5.3.100mdk.amd64.rpm
163af8675953560f0ffc38650971fd54 amd64/10.0/RPMS/gaim-encrypt-0.75-5.3.100mdk.amd64.rpm
8361be40fdbb0ed37be46fdf99885554 amd64/10.0/RPMS/gaim-festival-0.75-5.3.100mdk.amd64.rpm
7e618514ba49b043dce5e295240f7ef9 amd64/10.0/RPMS/gaim-perl-0.75-5.3.100mdk.amd64.rpm
2d21ba0e9402576f374a710946e7eae1 amd64/10.0/RPMS/lib64gaim-remote0-0.75-5.3.100mdk.amd64.rpm
4ae450fd3b03c6efd96ea2f62d9ab0d5 amd64/10.0/RPMS/lib64gaim-remote0-devel-0.75-5.3.100mdk.amd64.rpm
949b9d4232202401c724cb01fc220e1e amd64/10.0/SRPMS/gaim-0.75-5.3.100mdk.src.rpm

Vendor URL:  gaim.sourceforge.net/security/ (Links to External Site)
Cause:   Boundary error, Input validation error
Underlying OS:   Linux (Mandriva/Mandrake)

Message History:   This archive entry is a follow-up to the message listed below.
Aug 28 2004 Gaim Buffer Overflows in Groupware Messages, URLs, Hostname Lookups, and RTF Messages May Permit Remote Code Execution



 Source Message Contents

Date:  21 Oct 2004 20:47:02 -0000
Subject:  [Security Announce] MDKSA-2004:110 - Updated gaim packages fix


This is a multi-part message in MIME format...

------------=_1098392908-987-4367

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

                 Mandrakelinux Security Update Advisory
 _______________________________________________________________________

 Package name:           gaim
 Advisory ID:            MDKSA-2004:110
 Date:                   October 21st, 2004

 Affected versions:	 10.0
 ______________________________________________________________________

 Problem Description:

 More vulnerabilities have been discovered in the gaim instant
 messenger client.  The vulnerabilities pertinent to version 0.75,
 which is the version shipped with Mandrakelinux 10.0, are:  installing
 smiley themes could allow remote attackers to execute arbitrary
 commands via shell metacharacters in the filename of the tar file that
 is dragged to the smiley selector.  There is also a buffer overflow in
 the way gaim handles receiving very long URLs.
 
 The provided packages have been patched to fix these problems.  These
 issues, amongst others, have been fixed upstream in version 0.82.
 _______________________________________________________________________

 References:

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0784
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0785
 ______________________________________________________________________

 Updated Packages:
  
 Mandrakelinux 10.0:
 fb5e0402f4debc556bbd9415d96f9638  10.0/RPMS/gaim-0.75-5.3.100mdk.i586.rpm
 9b398cc925dabbf3cdc5f2dd412d09cb  10.0/RPMS/gaim-encrypt-0.75-5.3.100mdk.i586.rpm
 d27addd1e3d0392f1076cb26ff274af3  10.0/RPMS/gaim-festival-0.75-5.3.100mdk.i586.rpm
 2076ce789cfd20e8a09963d7966846d6  10.0/RPMS/gaim-perl-0.75-5.3.100mdk.i586.rpm
 e9bb68490f6e66f8f53602c646bfe6e8  10.0/RPMS/libgaim-remote0-0.75-5.3.100mdk.i586.rpm
 1fc1fb4b90b3772b315b84c35c9a91c1  10.0/RPMS/libgaim-remote0-devel-0.75-5.3.100mdk.i586.rpm
 949b9d4232202401c724cb01fc220e1e  10.0/SRPMS/gaim-0.75-5.3.100mdk.src.rpm

 Mandrakelinux 10.0/AMD64:
 63f64fdf9a464f06a6626b27ca7a523c  amd64/10.0/RPMS/gaim-0.75-5.3.100mdk.amd64.rpm
 163af8675953560f0ffc38650971fd54  amd64/10.0/RPMS/gaim-encrypt-0.75-5.3.100mdk.amd64.rpm
 8361be40fdbb0ed37be46fdf99885554  amd64/10.0/RPMS/gaim-festival-0.75-5.3.100mdk.amd64.rpm
 7e618514ba49b043dce5e295240f7ef9  amd64/10.0/RPMS/gaim-perl-0.75-5.3.100mdk.amd64.rpm
 2d21ba0e9402576f374a710946e7eae1  amd64/10.0/RPMS/lib64gaim-remote0-0.75-5.3.100mdk.amd64.rpm
 4ae450fd3b03c6efd96ea2f62d9ab0d5  amd64/10.0/RPMS/lib64gaim-remote0-devel-0.75-5.3.100mdk.amd64.rpm
 949b9d4232202401c724cb01fc220e1e  amd64/10.0/SRPMS/gaim-0.75-5.3.100mdk.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrakeUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandrakesoft for security.  You can obtain
 the GPG public key of the Mandrakelinux Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandrakelinux at:

  http://www.mandrakesoft.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_linux-mandrake.com

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Linux Mandrake Security Team
  <security linux-mandrake.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQFBeCBGmqjQ0CJFipgRAti0AKCv7fBEs0OBtlPKJHcbMnQTKAqSQQCg4iVm
3gOIs6fw5qxQU2MziVHuu+8=
=RzAH
-----END PGP SIGNATURE-----


------------=_1098392908-987-4367
Content-Type: text/plain; name="message.footer"
Content-Disposition: inline; filename="message.footer"
Content-Transfer-Encoding: 8bit

____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________

------------=_1098392908-987-4367--

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC