Gaim Remote Denial of Service Vulnerability
BID:12660
Info
Gaim Remote Denial of Service Vulnerability
| Bugtraq ID: | 12660 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0208 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2005 12:00AM |
| Updated: | Dec 22 2006 12:04AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Rob Flynn Gaim 1.1.3 Rob Flynn Gaim 1.1.2 Rob Flynn Gaim 1.1.1 Rob Flynn Gaim 1.0.2 Rob Flynn Gaim 1.0.1 Rob Flynn Gaim 1.0 Rob Flynn Gaim 0.77 Rob Flynn Gaim 0.59.8 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Peachtree Linux release 1 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 |
| Not Vulnerable: |
Rob Flynn Gaim 1.1.4 |
Discussion
Gaim Remote Denial of Service Vulnerability
Gaim is affected by a remote denial-of-service vulnerability. This issue can allow remote attackers to crash an affected client.
A vulnerability in the client arises during the parsing of malformed HTML data. This issue is nearly identical to that reported in BID 12589, but is a separate issue.
Gaim versions prior to 1.1.4 are affected by this issue.
Gaim is affected by a remote denial-of-service vulnerability. This issue can allow remote attackers to crash an affected client.
A vulnerability in the client arises during the parsing of malformed HTML data. This issue is nearly identical to that reported in BID 12589, but is a separate issue.
Gaim versions prior to 1.1.4 are affected by this issue.
Exploit / POC
Gaim Remote Denial of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gaim Remote Denial of Service Vulnerability
Solution:
Vendor upgrades are available. Please see the referenced advisories for more information.
Rob Flynn Gaim 0.59.8
Rob Flynn Gaim 0.77
Rob Flynn Gaim 1.0
Rob Flynn Gaim 1.0.1
Rob Flynn Gaim 1.0.2
Rob Flynn Gaim 1.1.1
Rob Flynn Gaim 1.1.2
Rob Flynn Gaim 1.1.3
Solution:
Vendor upgrades are available. Please see the referenced advisories for more information.
Rob Flynn Gaim 0.59.8
-
RedHat gaim-1.5.0-0.90.1.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/gaim-1.5.0-0.90 .1.legacy.i386.rpm
Rob Flynn Gaim 0.77
-
RedHat gaim-1.5.0-1.fc2.1.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/gaim-1.5.0-1.fc 2.1.legacy.i386.rpm
Rob Flynn Gaim 1.0
-
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php -
Ubuntu gaim_1.0.0-1ubuntu1.2_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_amd64.deb -
Ubuntu gaim_1.0.0-1ubuntu1.2_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_i386.deb -
Ubuntu gaim_1.0.0-1ubuntu1.2_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .2_powerpc.deb
Rob Flynn Gaim 1.0.1
-
RedHat gaim-1.1.4-0.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat gaim-1.1.4-0.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat gaim-1.1.4-0.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat gaim-1.1.4-0.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat gaim-debuginfo-1.1.4-0.FC2.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat gaim-debuginfo-1.1.4-0.FC2.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat gaim-debuginfo-1.1.4-0.FC3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
RedHat gaim-debuginfo-1.1.4-0.FC3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.0.2
-
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.1
-
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.2
-
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.3
-
Rob Flynn Gaim 1.1.4
http://gaim.sourceforge.net/downloads.php
References
Gaim Remote Denial of Service Vulnerability
References:
References:
- Project Homepage (Gaim)
- Remote DoS on receiving malformed HTML (Feb.24) (Gaim)
- RHSA-2005:215-11 - gaim security update (RedHat)
- [PLSN-0002] - Multiple vulnerabilities in Gaim (Peachtree Linux Security Team
)