Subject: CVS commit: pkgsrc/chat/gaim
From: Marc Recht
Date: 2004-01-27 02:24:52
Message id: 20040127012452.439ED2DA1D@cvs.netbsd.org

Log Message:
12 vulnerabilities were found in the instant messenger GAIM that allow remote \ 
compromise.
The 12 identified problems range from simple standard stack overflows, over heap \ 
overflows to an integer overflow that can be abused to cause a heap overflow. \ 
Due to the nature of instant messaging some of these bugs require \ 
man-in-the-middle attacks between client and server. But the underlying \ 
protocols are easy to implement and MIM attacks on ordinary TCP sessions is \ 
afairly simple task.

Please see http://security.e-matters.de/advisories/012004.html
for more details.

Apply the fix posted in that advisory (originally by the FreeBSD security
team) and bump PKGREVISION to 1.

Files:
RevisionActionfile
1.51modifypkgsrc/chat/gaim/Makefile
1.38modifypkgsrc/chat/gaim/distinfo
1.17modifypkgsrc/chat/gaim/patches/patch-aa
1.6addpkgsrc/chat/gaim/patches/patch-ab
1.5addpkgsrc/chat/gaim/patches/patch-ac
1.1addpkgsrc/chat/gaim/patches/patch-ad