Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51229
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2002:191
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2002:191.

Updated gaim packages are now available for Red Hat Linux Advanced Server.
These updates fix a vulnerability in the default URL handler.

Gaim is an all-in-one instant messaging client that lets you use a number of
messaging protocols such as AIM, ICQ, and Yahoo, all at once.

Versions of gaim prior to 0.59.1 contain a bug in the URL handler of
the manual browser option. A link can be carefully crafted to contain
an arbitrary shell script which will be executed if the user clicks on
the link.

Users of gaim should update to these errata packages containing gaim
0.59.1 which is not vulnerable to this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2002-191.html
http://gaim.sourceforge.net/ChangeLog

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 5574
Common Vulnerability Exposure (CVE) ID: CVE-2002-0989
http://www.securityfocus.com/bid/5574
Bugtraq: 20020827 GLSA: gaim (Google Search)
http://marc.info/?l=bugtraq&m=103046442403404&w=2
Conectiva Linux advisory: CLA-2002:521
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000521
Debian Security Information: DSA-158 (Google Search)
http://www.debian.org/security/2002/dsa-158
FreeBSD Security Advisory: FreeBSD-SN-02:06
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:06.asc
HPdes Security Advisory: HPSBTL0209-067
http://online.securityfocus.com/advisories/4471
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:054
http://www.osvdb.org/5033
http://www.redhat.com/support/errata/RHSA-2002-189.html
http://www.redhat.com/support/errata/RHSA-2002-190.html
http://www.redhat.com/support/errata/RHSA-2002-191.html
http://www.redhat.com/support/errata/RHSA-2003-156.html
http://www.iss.net/security_center/static/9978.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.