Mandrake Linux Security Advisory : gaim (MDKSA-2005:139)
High Nessus Plugin ID 19896
SynopsisThe remote Mandrake Linux host is missing one or more security updates.
DescriptionYet more vulnerabilities have been discovered in the gaim IM client.
Invalid characters in a sent file can cause Gaim to crash on some systems (CVE-2005-2102); a remote AIM or ICQ user can cause a buffer overflow in Gaim by setting an away message containing many AIM substitution strings (CVE-2005-2103); a memory alignment bug in the library used by Gaim to access the Gadu-Gadu network can result in a buffer overflow on non-x86 architecture systems (CVE-2005-2370).
These problems have been corrected in gaim 1.5.0 which is provided with this update.
SolutionUpdate the affected packages.