Gaim Jabber File Request Remote Denial Of Service Vulnerability
BID:13004
Info
Gaim Jabber File Request Remote Denial Of Service Vulnerability
| Bugtraq ID: | 13004 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-0967 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 05 2005 12:00AM |
| Updated: | Feb 28 2007 09:26PM |
| Credit: | Discovery of this issue is credited to Marcus. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Slackware Linux 10.1 SGI ProPack 3.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Rob Flynn Gaim 1.2 Rob Flynn Gaim 1.1.4 Rob Flynn Gaim 1.1.3 Rob Flynn Gaim 1.1.2 Rob Flynn Gaim 1.1.1 Rob Flynn Gaim 1.0.2 Rob Flynn Gaim 1.0.1 Rob Flynn Gaim 1.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Peachtree Linux release 1 |
| Not Vulnerable: |
Rob Flynn Gaim 1.2.1 |
Discussion
Gaim Jabber File Request Remote Denial Of Service Vulnerability
Gaim is reported prone to a remote denial-of-service vulnerability. The issue manifests itself when the Gaim client handles an unspecified Jabber file transfer request, triggering an out-of-bounds read operation.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
This vulnerability is reported to affect Gaim version 1.2.0 and previous versions.
Gaim is reported prone to a remote denial-of-service vulnerability. The issue manifests itself when the Gaim client handles an unspecified Jabber file transfer request, triggering an out-of-bounds read operation.
A remote attacker may exploit this vulnerability to deny service for legitimate users.
This vulnerability is reported to affect Gaim version 1.2.0 and previous versions.
Exploit / POC
Gaim Jabber File Request Remote Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gaim Jabber File Request Remote Denial Of Service Vulnerability
Solution:
Vendor upgrades are available. Please see the referenced advisories for more information.
Rob Flynn Gaim 1.0
Rob Flynn Gaim 1.0.1
Rob Flynn Gaim 1.0.2
Rob Flynn Gaim 1.1.1
Rob Flynn Gaim 1.1.2
Rob Flynn Gaim 1.1.3
Rob Flynn Gaim 1.1.4
Rob Flynn Gaim 1.2
Slackware Linux 10.1
Solution:
Vendor upgrades are available. Please see the referenced advisories for more information.
Rob Flynn Gaim 1.0
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php -
Ubuntu gaim_1.0.0-1ubuntu1.4_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .4_amd64.deb -
Ubuntu gaim_1.0.0-1ubuntu1.4_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .4_i386.deb -
Ubuntu gaim_1.0.0-1ubuntu1.4_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.0.0-1ubuntu1 .4_powerpc.deb
Rob Flynn Gaim 1.0.1
-
Fedora gaim-1.2.1-1.fc3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-1.2.1-1.fc3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-debuginfo-1.2.1-1.fc3.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora gaim-debuginfo-1.2.1-1.fc3.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.0.2
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.1
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.2
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.3
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Rob Flynn Gaim 1.1.4
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php -
Ubuntu gaim-data_1.1.4-1ubuntu4.1_all.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim-data_1.1.4-1ub untu4.1_all.deb -
Ubuntu gaim-dev_1.1.4-1ubuntu4.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim-dev_1.1.4-1ubu ntu4.1_amd64.deb -
Ubuntu gaim-dev_1.1.4-1ubuntu4.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim-dev_1.1.4-1ubu ntu4.1_i386.deb -
Ubuntu gaim-dev_1.1.4-1ubuntu4.1_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim-dev_1.1.4-1ubu ntu4.1_ia64.deb -
Ubuntu gaim-dev_1.1.4-1ubuntu4.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim-dev_1.1.4-1ubu ntu4.1_powerpc.deb -
Ubuntu gaim_1.1.4-1ubuntu4.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.1.4-1ubuntu4 .1_amd64.deb -
Ubuntu gaim_1.1.4-1ubuntu4.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.1.4-1ubuntu4 .1_i386.deb -
Ubuntu gaim_1.1.4-1ubuntu4.1_ia64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.1.4-1ubuntu4 .1_ia64.deb -
Ubuntu gaim_1.1.4-1ubuntu4.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/g/gaim/gaim_1.1.4-1ubuntu4 .1_powerpc.deb
Rob Flynn Gaim 1.2
-
Rob Flynn Gaim 1.2.1
http://gaim.sourceforge.net/downloads.php
Slackware Linux 10.1
-
Slackware gaim-1.3.0-i486-1.tgz
Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ gaim-1.3.0-i486-1.tgz
References
Gaim Jabber File Request Remote Denial Of Service Vulnerability
References:
References:
- Gaim website (Rob Flynn
) - Jabber remote crash (Rob Flynn)
- RHSA-2005:365-06 - gaim security update (RedHat)
- [PLSN-0002] - Multiple vulnerabilities in Gaim (Peachtree Linux Security Team
)