Summary
The remote host is missing updates announced in
advisory GLSA 200401-04.
Solution
All users are recommended to upgrade GAIM to 0.75-r7.
$> emerge sync
$> emerge -pv '>=net-im/gaim-0.75-r7'
$> emerge '>=net-im/gaim-0.75-r7'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200401-04 http://bugs.gentoo.org/show_bug.cgi?id=39470
http://www.securityfocus.com/archive/1/351235/2004-01-23/2004-01-29/0
Insight
Various overflows in the handling of AIM DirectIM packets was revealed in GAIM that could lead to a remote compromise of the IM client.
Severity
Classification
-
CVE CVE-2004-0005, CVE-2004-0006, CVE-2004-0007, CVE-2004-0008 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities