Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Xbox One hardware and specs: 8-core CPU, 8GB RAM, 500GB hard drive and more
· Tim Cook: US-made Macs will be assembled in Texas
· Microsoft software satisfaction slumps
· Photos of Likely 802.11ac 'Gigabit Wi-Fi' Card From Next-Generation iMac Surface
· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises
· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen

Upcoming News
· Long-Awaited Xbox One Makes Its Debut, Microsoft Aims for All-in-One Entertainment Center
· Removing and Wiping Drivers Guide @ OCC
· Oregon Scientific ATC9K Action Camera
· [RHSA-2013:0847-01] Moderate: kernel security and bug fix update
· How to Install AMD Drivers Guide @ OCC
· Lenovo Y500 Gaming Notebook Review: The Best Mobile Gaming Value Around?
· [security-announce] SUSE-SU-2013:0814-1: important: Security update for java-1_6_0-openjdk
· Intel Linux OpenGL Driver Leading Over Apple OS X
· SteelSeries Joint Giveaway - Three 6Gv2 Mechanical Gaming Keyboards Up For Grabs
· ZOTAC GeForce GTX TITAN AMP! Edition 6144 MB @ techPowerUp

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6416 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 675 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4534 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 739 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1126 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » August 2005 » USN-162-1: ekg and Gadu library vulnerabilities

USN-162-1: ekg and Gadu library vulnerabilities

Posted by Philipp Esselbach on: 08/09/2005 03:53 AM [ Print | 0 comment(s) ]

An ekg and Gadu library security update has been released for Ubuntu Linux 5.04

===========================================================
Ubuntu Security Notice USN-162-1 August 08, 2005
ekg vulnerabilities
CAN-2005-1850, CAN-2005-1851, CAN-2005-1852, CAN-2005-1916,
CAN-2005-2369, CAN-2005-2370, CAN-2005-2448
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.04 (Hoary Hedgehog)

The following packages are affected:

ekg
libgadu3

The problem can be corrected by upgrading the affected package to version 1:1.5-4ubuntu1.2. In general, a standard system upgrade is sufficient to effect the necessary changes. If you use the Instant Messaging application "Kopete", you need to restart it after the upgrade since it uses the libgadu3 library package.




Details follow:

Marcin Owsiany and Wojtek Kaniewski discovered that some contributed scripts (contrib/ekgh, contrib/ekgnv.sh, and contrib/getekg.sh) in the ekg package created temporary files in an insecure way, which allowed exploitation of a race condition to create or overwrite files with the privileges of the user invoking the script. (CAN-2005-1850)

Marcin Owsiany and Wojtek Kaniewski discovered a shell command injection vulnerability in a contributed utility (contrib/scripts/ekgbot-pre1.py). By sending specially crafted content to the bot, an attacker could exploit this to execute arbitrary code with the privileges of the user running ekgbot. (CAN-2005-1851)

Marcin Alusarz discovered an integer overflow in the Gadu library. By sending a specially crafted incoming message, a remote attacker could execute arbitrary code with the privileges of the application using libgadu. (CAN-2005-1852)

Eric Romang discovered that another contributed script (contrib/scripts/linki.py) created temporary files in an insecure way, which allowed exploitation of a race condition to create or overwrite files with the privileges of the user invoking the script. (CAN-2005-1916)

Grzegorz Jakiewicz discovered several integer overflows in the Gadu library. A remote attacker could exploit this to crash the Gadu client application or even execute arbitrary code with the privileges of the user by sending specially crafted messages. (CAN-2005-2369)

Szymon Zygmunt and Micha Bartoszkiewicz discovered a memory alignment error in the Gadu library. By sending specially crafted messages, a remote attacker could crash the application using the library. (CAN-2005-2370)

Marcin Alusarz discovered that the Gadu library did not properly handle endianess conversion in some cases. This caused invalid behavior on big endian architectures. The only affected supported architecture is powerpc. (CAN-2005-2448)


Source archives:

http://security.ubuntu.com/ubuntu/pool/main/e/ekg/ekg_1.5-4ubuntu1.2.di
ff.gz
Size/MD5: 66554 94d10dc8d262c773b75e273a89af21ca
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/ekg_1.5-4ubuntu1.2.dsc
Size/MD5: 742 2d609b048a3a7a89c245fec78380ce4f
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/ekg_1.5.orig.tar.gz
Size/MD5: 483606 721ebfe7b13e9531b30d558465e6695f

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/e/ekg/ekg_1.5-4ubuntu1.
2_amd64.deb
Size/MD5: 271816 c2b9ca69a9fb3a16933e579203bf68d1
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu-dev_1.5-4ubun
tu1.2_amd64.deb
Size/MD5: 123200 86b3b97242b9158b4df875178f0b44a7
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu3_1.5-4ubuntu1
.2_amd64.deb
Size/MD5: 60758 cdc991747fe23f371d5a6ab1d0372e41

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/e/ekg/ekg_1.5-4ubuntu1.
2_i386.deb
Size/MD5: 257060 b4e34e91748683784dd4afd82d1e4f3a
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu-dev_1.5-4ubun
tu1.2_i386.deb
Size/MD5: 118968 1d862c2b0f6631b06a30ecea3c6059f2
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu3_1.5-4ubuntu1
.2_i386.deb
Size/MD5: 59244 cd0e3173ca11c6193c3890565efcdf19

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/e/ekg/ekg_1.5-4ubuntu1.
2_powerpc.deb
Size/MD5: 272874 eddb8860f495f69c8703ae13021bcda4
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu-dev_1.5-4ubun
tu1.2_powerpc.deb
Size/MD5: 125292 52117bda28de8afecd190a11430f0fdc
http://security.ubuntu.com/ubuntu/pool/main/e/ekg/libgadu3_1.5-4ubuntu1
.2_powerpc.deb
Size/MD5: 61946 96965240cde5f35d1561adcc13366636


Bookmark and Share

« Metacity 2.11.2 · FEAR first impressions and benchmarks @ bit-tech »

Linux Compatible » News » August 2005 » USN-162-1: ekg and Gadu library vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition