-
Secunia Advisory 16379
Gaim Away Message Buffer Overflow and Denial of Service- Criticality: High
- Description: A vulnerability and a weakness have been reported in Gaim, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
- An error in the handling of away messages can be exploited to cause a heap-based buffer overflow by sending a specially crafted away message to a user logged into AIM or ICQ.
Successful exploitation allows execution of arbitrary code.
- An error in the handling of file transfers can be exploited to crash the application by attempting to upload a file with a non-UTF8 filename to a user logged into AIM or ICQ.
- An error in the handling of away messages can be exploited to cause a heap-based buffer overflow by sending a specially crafted away message to a user logged into AIM or ICQ.
- Secunia Advisory: http://secunia.com/advisories/16379/
-
Secunia Advisory 16384
Red Hat update for gaim- Criticality: High
- Description: Red Hat has issued an update for gaim. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
- Secunia Advisory: http://secunia.com/advisories/16384/
-
Secunia Advisory 16386
WordPress "cache_lastpostdate" PHP Code Insertion- Criticality: High
- Description: kartoffelguru has discovered a vulnerability in WordPress, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "cache_lastpostdate" parameter via cookies is not properly sanitised before being used. This can be exploited to inject arbitrary PHP script code.
- Secunia Advisory: http://secunia.com/advisories/16386/
-
Secunia Advisory 16387
Red Hat update for gaim- Criticality: High
- Description: Red Hat has issued an update for gaim. This fixes a vulnerability and two weaknesses, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system.
- Secunia Advisory: http://secunia.com/advisories/16387/
