int(599)

Vulnerability Bulletins


Actualización de Gaim soluciona varias vulnerabilidades

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Gaim (<=0.75)

Description

Gaim es una aplicación de mensajería instantánea con soporte para múltiples protocolos.

Varias vulnerabilidades han sido descubiertas en la versión 0.75 y anteriores de este software, entre ellas varios desbordamientos de búfer que podrían llegar a provocar la ejecución remota de código.

Solution

Si lo desea, aplique los mecanismos de actualización propios de su distribución, o bien baje las fuentes del software y compílelo usted mismo.


Actualización software

Gaim
parche Gaim (<=0.75)
http://gaim.sourceforge.net/gaim-0.75.patch

Linux RedHat

Redhat 9.0
i386
ftp://updates.redhat.com/9/en/os/i386/gaim-0.75-0.9.0.i386.rpm
SRPMS
ftp://updates.redhat.com/9/en/os/SRPMS/gaim-0.75-0.9.0.src.rpm

Linux Mandrake

Mandrake 9.1
i386
ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/gaim-0.75-1.2.91mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/gaim-encrypt-0.75-1.2.91mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/libgaim-remote0-0.75-1.2.91mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/RPMS/libgaim-remote0-devel-0.75-1.2.91mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.1/SRPMS/gaim-0.75-1.2.91mdk.src.rpm
PPC
ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/gaim-0.75-1.2.91mdk.ppc.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/gaim-encrypt-0.75-1.2.91mdk.ppc.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/libgaim-remote0-0.75-1.2.91mdk.ppc.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/RPMS/libgaim-remote0-devel-0.75-1.2.91mdk.ppc.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/ppc/9.1/SRPMS/gaim-0.75-1.2.91mdk.src.rpm

Mandrake 9.2
i386
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/gaim-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/gaim-encrypt-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/gaim-festival-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/gaim-perl-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/libgaim-remote0-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/RPMS/libgaim-remote0-devel-0.75-1.2.92mdk.i586.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/9.2/SRPMS/gaim-0.75-1.2.92mdk.src.rpm
AMD64
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/gaim-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/gaim-encrypt-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/gaim-festival-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/gaim-perl-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/lib64gaim-remote0-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/RPMS/lib64gaim-remote0-devel-0.75-1.2.92mdk.amd64.rpm
ftp://ftp.rediris.es/mirror/mandrake/updates/amd64/9.2/SRPMS/gaim-0.75-1.2.92mdk.src.rpm

Linux SuSe

SuSe 9.0
i386
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/gaim-0.67-65.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/gaim-0.67-65.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/src/gaim-0.67-65.src.rpm

SuSe 8.2
i386
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/gaim-0.59.8-60.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/gaim-0.59.8-60.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/src/gaim-0.59.8-60.src.rpm

SuSe 8.1
i386
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/gaim-0.59-158.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/gaim-0.59-158.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/gaim-0.59-158.src.rpm

SuSe 8.0
i386
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gnm3/gaim-0.50-187.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/gnm3/gaim-0.50-187.i386.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/gaim-0.50-187.src.rpm

Linux Debian

Debian 3.0
Source:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4.dsc
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4.diff.gz
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_alpha.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_alpha.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_arm.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_arm.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_i386.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_i386.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_ia64.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_ia64.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_hppa.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_hppa.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_m68k.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_m68k.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_mips.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_mips.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_mipsel.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_powerpc.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_s390.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_s390.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/g/gaim/gaim_0.58-2.4_sparc.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-common_0.58-2.4_sparc.deb
http://security.debian.org/pool/updates/main/g/gaim/gaim-gnome_0.58-2.4_sparc.deb

Standar resources

Property Value
CVE CAN-2004-0006
CAN-2004-0007
CAN-2004-0008
BID

Other resources

RHSA-2004:032-04 Updated Gaim packages fix various vulnerabiliies
https://rhn.redhat.com/errata/RHSA-2004-032.html

SUSE Security Announcement: gaim (SuSE-SA:2004:004)
http://www.suse.de/de/security/2004_04_gaim.html

MandrakeSoft Security Advisory MDKSA-2004:006-1 : gaim
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:006-1

Debian Security Advisory DSA 434-1gaim -- several vulnerabilities
http://www.debian.org/security/2004/dsa-434

Version history

Version Comments Date
1.0 Aviso emitido 2004-02-05
Ministerio de Defensa
CNI
CCN
CCN-CERT