Subject: CVS commit: pkgsrc/chat/gaim
From: Lubomir Sedlacik
Date: 2005-08-10 18:13:34
Message id: 20050810161334.3AF9B2DA27@cvs.netbsd.org

Log Message:
Security fixes for CAN-2005-2102 and CAN-2005-2103.

- An error in the handling of away messages can be exploited to cause
  a heap-based buffer overflow by sending a specially crafted away message
  to a user logged into AIM or ICQ.

  Successful exploitation allows execution of arbitrary code.

- An error in the handling of file transfers can be exploited to crash
  the application by attempting to upload a file with a non-UTF8 filename
  to a user logged into AIM or ICQ.

Patches from RedHat.

Files:
RevisionActionfile
1.94modifypkgsrc/chat/gaim/Makefile
1.7modifypkgsrc/chat/gaim/buildlink3.mk
1.68modifypkgsrc/chat/gaim/distinfo
1.1addpkgsrc/chat/gaim/patches/patch-af
1.1addpkgsrc/chat/gaim/patches/patch-ag