Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
GNU C could be made to execute arbitrary code or cause a crash if it received a specially crafted input.. =========================================================================Ubuntu Security Notice USN-4218-1 December 10, 2019 eglibc vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: GNU C could be made to execute arbitrary code or cause a crash if it received a specially crafted input. Software Description: - eglibc: GNU C Library Details: Jakub Wilk discovered that GNU C incorrectly handled certain memory alignments. An attacker could possibly use this issue to execute arbitrary code or cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: libc6 2.19-0ubuntu6.15+esm1 Ubuntu 12.04 ESM: libc6 2.15-0ubuntu10.22 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4218-1 CVE-2018-6485 . Critical advisory for Ubuntu ESM subscribers regarding eglibc flaw that enables potential code execution or system instability.. Ubuntu ESM, eglibc update, security advisory, memory alignment, arbitrary execution. . Severity: Critical. LinuxSecurity.com Team
New gaim packages are available for Slackware 9.0, 9.1, 10.0, 10.1, and -current to fix some security issues. including: AIM/ICQ away message buffer overflow AIM/ICQ non-UTF-8 filename crash . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] gaim (SSA:2005-242-03) New gaim packages are available for Slackware 9.0, 9.1, 10.0, 10.1, and -current to fix some security issues. including: AIM/ICQ away message buffer overflow AIM/ICQ non-UTF-8 filename crash Gadu-Gadu memory alignment bug Sites that use GAIM should upgrade to the new version. More details about these issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CAN-2005-2103 https://www.cve.org/CVERecord?id=CAN-2005-2102 https://www.cve.org/CVERecord?id=CAN-2005-2370 Here are the details from the Slackware 10.1 ChangeLog: +--------------------------+ patches/packages/gaim-1.5.0-i486-1.tgz: Upgraded to gaim-1.5.0. This fixes some more security issues. For more information, see: https://www.cve.org/CVERecord?id=CAN-2005-2103 https://www.cve.org/CVERecord?id=CAN-2005-2102 https://www.cve.org/CVERecord?id=CAN-2005-2370 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/gaim-1.5.0-i386-1.tgz Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/gaim-1.5.0-i486-1.tgz Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/gaim-1.5.0-i486-1.tgz Updated package for Slackware 10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/gaim-1.5.0-i486-1.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 9.0 package: 676bad766cfddb50c7453554d66b1748 gaim-1.5.0-i386-1.tgz Slackware 9.1 package: d2cc0baba627ba9dbf3f218bdeacc630 gaim-1.5.0-i486-1.tgz Slackware 10.0 package: 98d55471ed0a2f9def7fcded90860839 gaim-1.5.0-i486-1.tgz Slackware 10.1 package: bc6891f4acb22530c472218f5d9493fb gaim-1.5.0-i486-1.tgz Slackware -current package: b9a55d4359183b81e1150bea6e13b61e gaim-1.5.0-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg gaim-1.5.0-i486-1.tgz +-----+ . Gaim software versions refreshed for Slackware to mitigate AIM/ICQ buffer overflow vulnerabilities and various other concerns; update advised.. Gaim Security Update, Slackware Packages, AIM Crash Fix, Memory Alignment Bug. . LinuxSecurity.com Team
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-751 2005-08-17 ---------------------------------------------------------------------Product : Fedora Core 4 Name : gaim Version : 1.5.0 Release : 1.fc4 Summary : A GTK+ clone of the AOL Instant Messenger client. Description : Gaim is a clone of America Online's Instant Messenger client. It features nearly all of the functionality of the official AIM client while also being smaller, faster, and commercial-free. ---------------------------------------------------------------------Update Information: Please see the Changelog details and security information at the upstream Gaim Project site. ---------------------------------------------------------------------* Thu Aug 11 2005 Warren Togami - 1:1.5.0-1 - 1.5.0 security and bug fixes CAN-2005-2370 Gadu-Gadu memory alignment bug CAN-2005-2102 AIM/ICQ non-UTF-8 Filename Crash CAN-2005-2103 AIM/ICQ away message buffer overflow * Tue Aug 9 2005 Jeremy Katz - 1:1.4.0-7 - rebuild for new evolution-data-server * Mon Aug 1 2005 Warren Togami 1:1.4.0-6 - FC5+ bash regex replace for -fstack-protector-all (mharris) * Sun Jul 31 2005 Warren Togami 1:1.4.0-5 - FC5+ automatic -fstack-protector-all switch - 150: MSN buddy names with space disconnect and profile corruption (supercedes patch 149) - 151: Gadu Gadu memory alignment crash - 152: Rename Group Merge crash - 153: mailto: parse crash (util.c) - 154: mailto: parse crash (MSN) - 155: mailto: parse crash (Zephyr) ---------------------------------------------------------------------This update can be downloaded from: 7c9ae8871169b9b52a165be73b886536 SRPMS/gaim-1.5.0-1.fc4.src.rpm 4903d7d71010d3f3e6ef83a42a9e8fdd ppc/gaim-1.5.0-1.fc4.ppc.rpm e47699be139e84eb7c02758b3ce8f2e9 ppc/debug/gaim-debuginfo-1.5.0-1.fc4.ppc.rpm c175e173ace9cb5cfdae196938c1a0f6 x86_64/gaim-1.5.0-1.fc4.x86_64.rpm 03e36cdf98f41d96d95c4aa7284b101c x86_64/debug/gaim-debuginfo-1.5.0-1.fc4.x86_64.rpm 939242b073bc6a64eeefe2d1ccfa4484 i386/gaim-1.5.0-1.fc4.i386.rpm ea6e8adf567e8288ead13b9044989494 i386/debug/gaim-debuginfo-1.5.0-1.fc4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-750 2005-08-17 ---------------------------------------------------------------------Product : Fedora Core 3 Name : gaim Version : 1.5.0 Release : 1.fc3 Summary : A GTK+ clone of the AOL Instant Messenger client. Description : Gaim is a clone of America Online's Instant Messenger client. It features nearly all of the functionality of the official AIM client while also being smaller, faster, and commercial-free. ---------------------------------------------------------------------Update Information: Please see the Changelog details and security information at the upstream Gaim Project site. ---------------------------------------------------------------------* Thu Aug 11 2005 Warren Togami - 1:1.5.0-1 - 1.5.0 security and bug fixes CAN-2005-2370 Gadu-Gadu memory alignment bug CAN-2005-2102 AIM/ICQ non-UTF-8 Filename Crash CAN-2005-2103 AIM/ICQ away message buffer overflow * Tue Aug 9 2005 Jeremy Katz - 1:1.4.0-7 - rebuild for new evolution-data-server * Mon Aug 1 2005 Warren Togami 1:1.4.0-6 - FC5+ bash regex replace for -fstack-protector-all (mharris) * Sun Jul 31 2005 Warren Togami 1:1.4.0-5 - FC5+ automatic -fstack-protector-all switch - 150: MSN buddy names with space disconnect and profile corruption (supercedes patch 149) - 151: Gadu Gadu memory alignment crash - 152: Rename Group Merge crash - 153: mailto: parse crash (util.c) - 154: mailto: parse crash (MSN) - 155: mailto: parse crash (Zephyr) ---------------------------------------------------------------------This update can be downloaded from: 709dfeddc2b8ae02448478518ad6579c SRPMS/gaim-1.5.0-1.fc3.src.rpm 788f4fe7561131aaf406c8bb7a473e50 x86_64/gaim-1.5.0-1.fc3.x86_64.rpm 17ac20c2e95577cbe268bff717d08bcc x86_64/debug/gaim-debuginfo-1.5.0-1.fc3.x86_64.rpm d22007b8bf36278a4511ccb164f91de1 i386/gaim-1.5.0-1.fc3.i386.rpm 7ae413d0f5b18409f64f63887574f748 i386/debug/gaim-debuginfo-1.5.0-1.fc3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.