A format string vulnerability in Ekiga may allow the remote execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200703-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Ekiga: Format string vulnerability Date: March 29, 2007 Bugs: #167643 ID: 200703-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A format string vulnerability in Ekiga may allow the remote execution of arbitrary code. Background ========= Ekiga is an open source VoIP and video conferencing application. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-im/ekiga < 2.0.7 > = 2.0.7 Description ========== Mu Security has discovered that Ekiga fails to implement formatted printing correctly. Impact ===== An attacker could exploit this vulnerability to crash Ekiga and potentially execute arbitrary code by sending a specially crafted Q.931 SETUP packet to a victim. Workaround ========= There is no known workaround at this time. Resolution ========= All Ekiga users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-im/ekiga-2.0.7" References ========= [ 1 ] CVE-2007-1006 https://www.cve.org/CVERecord?id=CVE-2007-1006 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200703-25 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentialityand security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated ekiga packages that fix security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having critical security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Critical: ekiga security update Advisory ID: RHSA-2007:0087-02 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0087.html Issue date: 2007-03-13 Updated on: 2007-03-14 Product: Red Hat Enterprise Linux CVE Names: CVE-2007-0999 CVE-2007-1006 - ---------------------------------------------------------------------1. Summary: Updated ekiga packages that fix security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64 3. Problem description: Ekiga is a tool to communicate with video and audio over the Internet. Format string flaws were found in the way Ekiga processes certain messages. If a user is running Ekiga, a remote attacker who can connect to Ekiga could trigger this flaw and potentially execute arbitrary code with the privileges of the user. (CVE-2007-0999, CVE-2007-1006) Users of Ekiga should upgrade to these updated packages which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 229262 - CVE-2007-0999 Ekiga format string flaw (CVE-2007-1006) 6. RPMs required: Red Hat Enterprise LinuxDesktop (v. 5 client): SRPMS: 8b8f08aca0e186151d75393b4f0d530f ekiga-2.0.2-7.0.2.src.rpm i386: 81bdab90f5d9f115409057e2802416a7 ekiga-2.0.2-7.0.2.i386.rpm bcc1c8be2530a366044d57306f84f189 ekiga-debuginfo-2.0.2-7.0.2.i386.rpm x86_64: a8f36138642f048f9622bfca2b3dbad2 ekiga-2.0.2-7.0.2.x86_64.rpm 4e0f2bb06b98810ef5a98978877010ab ekiga-debuginfo-2.0.2-7.0.2.x86_64.rpm RHEL Optional Productivity Applications (v. 5 server): SRPMS: 8b8f08aca0e186151d75393b4f0d530f ekiga-2.0.2-7.0.2.src.rpm i386: 81bdab90f5d9f115409057e2802416a7 ekiga-2.0.2-7.0.2.i386.rpm bcc1c8be2530a366044d57306f84f189 ekiga-debuginfo-2.0.2-7.0.2.i386.rpm x86_64: a8f36138642f048f9622bfca2b3dbad2 ekiga-2.0.2-7.0.2.x86_64.rpm 4e0f2bb06b98810ef5a98978877010ab ekiga-debuginfo-2.0.2-7.0.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2007-0999 https://www.cve.org/CVERecord?id=CVE-2007-1006 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2007 Red Hat, Inc. . Important announcement regarding ekiga in Red Hat Enterprise Linux 5, tackling serious security vulnerabilities and threats of remote execution.. Ekiga Update, Red Hat Security, Linux Update. . Severity: Critical. LinuxSecurity.com Team
It was discovered that Ekiga had format string vulnerabilities beyond those fixed in USN-426-1. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges. . =========================================================== Ubuntu Security Notice USN-434-1 March 09, 2007 ekiga, gnomemeeting vulnerability CVE-2007-0999 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: gnomemeeting 1.2.2-1ubuntu1.2 Ubuntu 6.06 LTS: ekiga 2.0.1-0ubuntu6.2 Ubuntu 6.10: ekiga 2.0.3-0ubuntu3.2 After a standard system upgrade you need to restart Ekiga or reboot your computer to effect the necessary changes. Details follow: It was discovered that Ekiga had format string vulnerabilities beyond those fixed in USN-426-1. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 13935 390ded46c12911e6ff7f0fb0b41648b1 Size/MD5: 1811 bfaea7c58d0be1c76fb15275584929d8 Size/MD5: 6059950 65fe2d6a31e63a37c5a6217206223192 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 1826502 ab68c7c0c54d6ea2288058f1cd850e0a i386 architecture (x86 compatible Intel/AMD) Size/MD5: 1802224 2323471938830841421f5758518444a0 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 181757861f4574c015fb133a7d223d68945ad87 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 1803946 ab636f2081b328f36025e99cea2f0cd3 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 26736 820ab04b4cb0423bb9d62f03bf3e4634 Size/MD5: 2090 921caa6df4e1ceeb79438b5f653992c6 Size/MD5: 5572709 9f0a2bcce380677e38b23991320df171 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3687974 428c44b190d3e1e6f97f8d3be08aa6fe i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3658256 2b4c80838f881af9780e65e5be79b26b powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3673874 44119593cb37df9ae0c759df26e9f5b3 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3661004 85ce6c1bc136e1e6699cfb501d537abd Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 27205 ae82839a944aa39b118b1fa6edda3f1c Size/MD5: 1837 90fa46619ab136f7e8d7086916c1bdc0 Size/MD5: 5749938 5ad3458d73d65c6502c312ff0c430a7c amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3689026 82e52fe078d8ab0102bf647d12cfe4cc i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3668638 4ebd1951ef9e4cc4860223e682c90541 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3676386 efcac25a055bb4cd5e776550c370880f sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3671020 41fda4e546004b1a7f456b286e2ce560 . Explore significant Ekiga security flaws present in Ubuntu builds following USN-434-1. Implement strategies to defend against potential threats.. Ekiga Vulnerability, Format String Issue, Ubuntu Security Update. . LinuxSecurity.com Team
Mu Security discovered a format string vulnerability in Ekiga. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges.. =========================================================== Ubuntu Security Notice USN-426-1 February 22, 2007 ekiga, gnomemeeting vulnerabilities CVE-2007-1006, CVE-2007-1007 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: gnomemeeting 1.2.2-1ubuntu1.1 Ubuntu 6.06 LTS: ekiga 2.0.1-0ubuntu6.1 Ubuntu 6.10: ekiga 2.0.3-0ubuntu3.1 After a standard system upgrade you need to restart Ekiga to effect the necessary changes. Details follow: Mu Security discovered a format string vulnerability in Ekiga. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 12465 55f41497417828ebef140cc0670a25d6 Size/MD5: 1811 63cc3478d280f09018f24ae55c3aa4ed Size/MD5: 6059950 65fe2d6a31e63a37c5a6217206223192 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 1826384 b3bfbd016a2e5fdd4f54ad639bef4e9b i386 architecture (x86 compatible Intel/AMD) Size/MD5: 1802170 3245abb98b202c2f6e7c27760723af5c powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 1817502 64236066ccb7f81fddb6728b158f0415 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 1803872 4ec0f28c58259ec9bf5aac2917a542f6 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 23489 9c1a9e42584e604667c474b441390dce Size/MD5: 2090 3eabad082fd143a10c5b3625db75562b Size/MD5: 5572709 9f0a2bcce380677e38b23991320df171 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3687800 943691c7d2d27e7d3156b050772ddd04 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3658022 fd451db8ed71af0d0caae71b0e55e7ec powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3673764 423bf587f00be062ffaf7b9cd62487c4 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3660784 b2ecd3a204168f67638000cd01c46a39 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 23822 fc9d0688739586606dc67efa1662070f Size/MD5: 1837 1da46e1bc9e1b820ee77cc32fc6c80d7 Size/MD5: 5749938 5ad3458d73d65c6502c312ff0c430a7c amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3688744 d4d26c59a8a1e90a82ad72961f3ffae8 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3668392 a12654dfa595f8cf37f89bf9b644dd44 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3676188 e2df269899f919673f2a7b7da7f0c8d1 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3670736 26e533cdcdb7efa2e891a5a335234f16 . =========================================================== Ubuntu Security Notice USN-426-1 Februar. ekiga, security, format, string, vulnerability, running, liste. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.