EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

BID:14345

Info

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

Bugtraq ID: 14345
Class: Boundary Condition Error
CVE: CVE-2005-1852
CVE-2005-2369
Remote: Yes
Local: No
Published: Jul 21 2005 12:00AM
Updated: Jul 12 2009 04:06PM
Credit: The vendor disclosed these issues.
Vulnerable: Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
SuSE SUSE Linux Enterprise Server 8
+ Linux kernel 2.4.21
+ Linux kernel 2.4.19
SuSE SUSE Linux Enterprise Server 7
+ Linux kernel 2.4.19
SuSE Linux Enterprise Server 9
SuSE Linux Desktop 1.0
Slackware Linux 10.1
Slackware Linux 10.0
Slackware Linux -current
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE LINUX Retail Solution 8.0
S.u.S.E. Open-Enterprise-Server 9.0
S.u.S.E. Novell Linux Desktop 9.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 8.2
S.u.S.E. Linux Professional 8.2
S.u.S.E. Linux Professional 7.3
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Personal 9.1
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Personal 8.2
S.u.S.E. Linux Enterprise Server for S/390 9.0
S.u.S.E. Linux Enterprise Server for S/390
KDE kopete 0.9.3
KDE kopete 0.9.2
KDE kopete 0.9.1
KDE kopete 0.9
KDE KDE 3.4.1
+ Redhat Fedora Core4
KDE KDE 3.4
KDE KDE 3.3.2
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
+ Debian Linux 3.1
+ Debian Linux 3.1
KDE KDE 3.3.2
KDE KDE 3.3.1
+ Redhat Fedora Core3
KDE KDE 3.3
KDE KDE 3.2.3
Gentoo Linux
ekg ekg 1.6 rc2
ekg ekg 1.6 rc1
ekg ekg 1.5
ekg ekg 1.4
ekg ekg 1.3
ekg ekg 1.1
ekg ekg 2005-06-05 22:03
ekg ekg 2005-04-11
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 amd64
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
Centericq Centericq 4.20
+ Debian Linux 3.1 sparc
+ Debian Linux 3.1 s/390
+ Debian Linux 3.1 ppc
+ Debian Linux 3.1 mipsel
+ Debian Linux 3.1 mips
+ Debian Linux 3.1 m68k
+ Debian Linux 3.1 ia-64
+ Debian Linux 3.1 ia-32
+ Debian Linux 3.1 hppa
+ Debian Linux 3.1 arm
+ Debian Linux 3.1 alpha
+ Debian Linux 3.1
Not Vulnerable: KDE kopete 0.10.3
KDE kopete 0.9.4
ekg ekg 1.6 rc3

Discussion

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

EKG libgadu is susceptible to multiple remote integer overflow vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input data prior to using it in memory allocation and copy operations.

Attackers may exploit these vulnerabilities to execute arbitrary machine code in the context of applications that utilize the affected library. Failed exploitation attempts likely result in crashed applications.

Exploit / POC

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

Solution:
The vendor has released an updated package containing a fixed libgadu.

KDE has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.

RedHat Fedora has released security advisories FEDORA-2005-624 and FEDORA-2005-623 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for information on obtaining and applying the appropriate updates.

Gentoo has released advisory GLSA 200507-23 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:

All Kopete users:
emerge --sync
emerge --ask --oneshot --verbose kde-base/kdenetwork

All KDE Split Ebuild Kopete users:
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kopete-3.4.1-r1"

Slackware Linux has released security advisory SSA:2005-203-02 addressing this issue. Please see the referenced advisory for further information.

Gentoo Linux has released security advisory GLSA 200507-26 addressing this issue for Gadu, Kadu, EKG, libgadu and CenterICQ. Gentoo recommends the following:
All GNU Gadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/gnugadu-2.2.6-r1"

All Kadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/kadu-0.4.1"

All EKG users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/ekg-1.6_rc3"

All libgadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-20050719"

All CenterICQ users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/centericq-4.20.0-r3"

CenterICQ is no longer distributed with Gadu Gadu support, affected
users are encouraged to migrate to an alternative package.

Debian advisory DSA 767-1 is available to address this issue. Please see the referenced advisory for more information.

Conectiva Linux has released security advisory CLSA-2005:989 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.

Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.

Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.

SUSE has released a security summary report (SUSE-SR:2005:019) addressing this and other issues. Please see the referenced advisory for further information.

Debian has released security advisory DSA 813-1 addressing this issue for centericq. Please see the referenced advisory for details on obtaining and applying the appropriate updates.


ekg ekg 2005-04-11

ekg ekg 2005-06-05 22:03

ekg ekg 1.1

ekg ekg 1.3

ekg ekg 1.4

ekg ekg 1.5

ekg ekg 1.6 rc2

ekg ekg 1.6 rc1

KDE KDE 3.2.3

KDE KDE 3.3.2

KDE KDE 3.4.1

Centericq Centericq 4.20

References

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report