Submitted by KeesCook on Wed, 2004-10-27 12:00
Referenced CVEs:
CAN-2004-0891
Description:
===========================================================
Ubuntu Security Notice USN-8-1 October 27, 2004
gaim vulnerabilities
CAN-2004-0891
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
gaim
The problem can be corrected by upgrading the affected package to
version 1:1.0.0-1ubuntu1.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
A buffer overflow and two remote crashes were recently discovered in
gaim's MSN protocol handler. An attacker could potentially execute
arbitrary code with the user's privileges by crafting and sending a
particular MSN message.


