Gaim Multiple Remote Denial of Service Vulnerabilities
BID:12589
Info
Gaim Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 12589 |
| Class: | Unknown |
| CVE: |
CVE-2005-0472 CVE-2005-0473 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2005 12:00AM |
| Updated: | Dec 22 2006 12:04AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Rob Flynn Gaim 1.1.2 Rob Flynn Gaim 1.1.1 Rob Flynn Gaim 1.0.2 Rob Flynn Gaim 1.0.1 Rob Flynn Gaim 1.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Peachtree Linux release 1 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Rob Flynn Gaim 1.1.3 |
Discussion
Gaim Multiple Remote Denial of Service Vulnerabilities
Gaim is prone to multiple remote denial-of-service vulnerabilities. These issues can allow remote attackers to crash an affected client.
The following specific issues were identified:
- Remote AIM or ICQ users may trigger a crash in a client by sending malformed SNAC packets.
- Another vulnerability in the client arises during the parsing of malformed HTML data.
Gaim versions prior to 1.1.3 are affected by these issues.
Gaim is prone to multiple remote denial-of-service vulnerabilities. These issues can allow remote attackers to crash an affected client.
The following specific issues were identified:
- Remote AIM or ICQ users may trigger a crash in a client by sending malformed SNAC packets.
- Another vulnerability in the client arises during the parsing of malformed HTML data.
Gaim versions prior to 1.1.3 are affected by these issues.
Exploit / POC
Gaim Multiple Remote Denial of Service Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Gaim Multiple Remote Denial of Service Vulnerabilities
Solution:
Vendor upgrades are available. Please see the referenced vendor advisories for further information.
Rob Flynn Gaim 1.0
Rob Flynn Gaim 1.0.1
Rob Flynn Gaim 1.0.2
Rob Flynn Gaim 1.1.1
Rob Flynn Gaim 1.1.2
Solution:
Vendor upgrades are available. Please see the referenced vendor advisories for further information.
Rob Flynn Gaim 1.0
-
Rob Flynn Gaim 1.1.3
http://gaim.sourceforge.net/downloads.php -
Ubuntu gaim_1.0.0-1ubuntu1.2_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_amd64.deb -
Ubuntu gaim_1.0.0-1ubuntu1.2_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_i386.deb -
Ubuntu gaim_1.0.0-1ubuntu1.2_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_powerpc.deb
Rob Flynn Gaim 1.0.1
-
Fedora gaim-1.1.3-1.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-1.1.3-1.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-debuginfo-1.1.3-1.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-debuginfo-1.1.3-1.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Rob Flynn Gaim 1.1.3
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.0.2
-
Rob Flynn Gaim 1.1.3
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.1
-
Rob Flynn Gaim 1.1.3
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.2
-
Rob Flynn Gaim 1.1.3
http://gaim.sourceforge.net/downloads.php
References
Gaim Multiple Remote Denial of Service Vulnerabilities
References:
References:
- AIM/ICQ remote denial of service (Gaim)
- Project Homepage (Gaim)
- Remote DoS on receiving malformed HTML (Gaim)
- RHSA-2005:215-11 - gaim security update (RedHat)
- [PLSN-0002] - Multiple vulnerabilities in Gaim (Peachtree Linux Security Team
)