Vulnerability Bulletins

DSA-2852 libgadu - heap-based buffer overflow

   
Affected software Debian
 
Yves Younan and Ryan Pentney discovered that libgadu, a library foraccessing the Gadu-Gadu instant messaging service, contained aninteger overflow leading to a buffer overflow. Attackers whichimpersonate the server could crash clients and potentially executearbitrary code.

More info:

http://www.debian.org/security/2014/dsa-2852