Descripción: | Description:
The remote host is missing updates announced in advisory CLA-2004:813.
Gaim is a multi-protocol, multi-platform instant messaging client.
Stefan Esser found[1] several remote vulnerabilities in Gaim. A remote attacker can use specially crafted network packets to exploit at least one of these vulnerabilities and execute arbitrary code in the context of the user running the program or cause a denial of service condition.
This update includes updated packages for Conectiva Linux 8 (Gaim 0.58.8) and Conectiva Linux 9 (Gaim 0.75). The vulnerabilities vary accordingly to the version used, but both are susceptible to remote attacks.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2004-0005, CVE-2004-0006, CVE-2004-0007 and CVE-2004-0008 to the issues discovered[2,3,4,5].
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'
http://security.e-matters.de/advisories/012004.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0005 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008 http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:813 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004
Risk factor : High
CVSS Score: 7.5
|