Gentoo Linux Security Advisory GLSA 200903-26
https://security.gentoo.org/
Severity: Normal
Title: TMSNC: Execution of arbitrary code
Date: March 12, 2009
Bugs: #229157
ID: 200903-26
Synopsis
=======
A buffer overflow in TMSNC might lead to the execution of arbitrary
code when processing an instant message.
Background
=========
TMSNC is a Textbased client for the MSN instant messaging protocol.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-im/tmsnc <= 0.3.2-r1 Vulnerable!
-------------------------------------------------------------------
NOTE: Certain packages are still vulnerable. Users should migrate
to another package if one is available or wait for the
existing packages to be marked stable by their
architecture maintainers.
==========
Nico Golde reported a stack-based buffer overflow when processing a MSN
packet with a UBX command containing a large UBX payload length field.
Impact
=====
A remote attacker could send a specially crafted message, poss...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.