==========================================================Ubuntu Security Notice USN-675-2          November 24, 2008
gaim vulnerability
CVE-2008-2927
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
  gaim                            1:1.5.0+1.5.1cvs20051015-1ubuntu10.1

After a standard system upgrade you need to restart Gaim to effect
the necessary changes.

Details follow:

It was discovered that Gaim did not properly handle certain malformed
messages in the MSN protocol handler. A remote attacker could send a specially
crafted message and possibly execute arbitrary code with user privileges.
(CVE-2008-2927)


Updated packages for Ubuntu 6.06 LTS:

  Source archives:

          Size/MD5:    34051 dde2b4483bc14d671228c8a512c9fd0c
          Size/MD5:     1061 0293c5a43587d3db41a2437da5254206
          Size/MD5:  4299145 949ae755e9be1af68eef6c09c36a7530

  Architecture independent packages:

          Size/MD5:   613282 4b5fd4fd6053473bf10db0634e993af0

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

          Size/MD5:   103266 05b0562cf37fb5c72063566134aa7369
          Size/MD5:   954258 7da66022c5ea3372d097f3f7404610f2

  i386 architecture (x86 compatible Intel/AMD):

          Size/MD5:   103248 81eebc45938e22bae57d3278682eee4b
          Size/MD5:   836378 82ecc0d267bb90f7669786ea2092cb93

  powerpc architecture (Apple Macintosh G3/G4/G5):

          Size/MD5:   103256 0fba1bcef36f3b6369effaf634c1a1df
          Size/MD5:   924628 5f2721e0fcbaf536e4bcbd7a74a6b06e

  sparc architecture (Sun SPARC/UltraSPARC):

          Size/MD5:   103250 e43bfb56d37e3617b7bee0644c3948a8
          Size/MD5:   856760 66a004eff69e42183c6c58d732761b86



Ubuntu: Gaim vulnerability

November 24, 2008
It was discovered that Gaim did not properly handle certain malformed messages in the MSN protocol handler

Summary

Update Instructions

References

Severity
gaim vulnerability

Package Information

Related News