Red Hat Security Advisory: gaim
| Synopsis: |
Updated Gaim packages fix various vulnerabilities |
| Advisory ID: |
RHSA-2004:032-01 |
| Issue date: |
2004-01-19 |
| Updated on: |
2004-01-23 |
| Product: |
Red Hat Linux |
| Keywords: |
gaim im |
| Cross references: |
|
| Obsoletes: |
|
| CVE Names: |
CAN-2004-0006 CAN-2004-0007 CAN-2004-0008 |
1. Topic:
Updated Gaim packages that fix a number of serious vulnerabilities are now
available.
2. Relevant releases/architectures:
Red Hat Linux 9 - i386
3. Problem description:
Gaim is an instant messenger client that can handle multiple protocols.
Stefan Esser audited the Gaim source code and found a number of bugs that
have security implications. Due to the nature of instant messaging many of these
bugs require man-in-the-middle attacks between client and server. However at
least one of the buffer overflows could be exploited by an attacker sending a
carefully-constructed malicious message through a server.
Full article: linux today