Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EKG LIbGadu Multiple Remote Integer Overflow Vulnerabilities

Solution:
The vendor has released an updated package containing a fixed libgadu.

KDE has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further information.

RedHat Fedora has released security advisories FEDORA-2005-624 and FEDORA-2005-623 addressing this issue for Fedora Core 3 and Core 4. Please see the referenced advisory for information on obtaining and applying the appropriate updates.

Gentoo has released advisory GLSA 200507-23 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:

All Kopete users:
emerge --sync
emerge --ask --oneshot --verbose kde-base/kdenetwork

All KDE Split Ebuild Kopete users:
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kopete-3.4.1-r1"

Slackware Linux has released security advisory SSA:2005-203-02 addressing this issue. Please see the referenced advisory for further information.

Gentoo Linux has released security advisory GLSA 200507-26 addressing this issue for Gadu, Kadu, EKG, libgadu and CenterICQ. Gentoo recommends the following:
All GNU Gadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/gnugadu-2.2.6-r1"

All Kadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/kadu-0.4.1"

All EKG users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/ekg-1.6_rc3"

All libgadu users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/libgadu-20050719"

All CenterICQ users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-im/centericq-4.20.0-r3"

CenterICQ is no longer distributed with Gadu Gadu support, affected
users are encouraged to migrate to an alternative package.

Debian advisory DSA 767-1 is available to address this issue. Please see the referenced advisory for more information.

Conectiva Linux has released security advisory CLSA-2005:989 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.

Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.

Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.

SUSE has released a security summary report (SUSE-SR:2005:019) addressing this and other issues. Please see the referenced advisory for further information.

Debian has released security advisory DSA 813-1 addressing this issue for centericq. Please see the referenced advisory for details on obtaining and applying the appropriate updates.


ekg ekg 2005-04-11

ekg ekg 2005-06-05 22:03

ekg ekg 1.1

ekg ekg 1.3

ekg ekg 1.4

ekg ekg 1.5

ekg ekg 1.6 rc2

ekg ekg 1.6 rc1

KDE KDE 3.2.3

KDE KDE 3.3.2

KDE KDE 3.4.1

Centericq Centericq 4.20







 

Privacy Statement
Copyright 2008, SecurityFocus