Re: CenterICQ IJHook.CC Remote Buffer Overflow Vulnerability

Julien Lemoine <[email protected]>
Newsgroups gmane.network.centericq
Message-ID <[email protected]>
Hello,

Debian package includes a fix for this buffer overflow (available on 
version >= 4.21.0-17).

Patch is available here :
http://www2.speedblue.org/download/security_TK53_livejournal.dpatch

There is also a potential segmentation fault in jabber module fixed in 
centericq >= 4.21.0-18.

Patch is available here :
http://www2.speedblue.org/download/potentialsegv_strstr.dpatch

Best Regards.
Julien Lemoine

* [email protected] <[email protected]> [2007-01-16 13:39:57 -0000]:

> I saw this security report on the Security Focus Vulnerability mailing list.
> 
> 
> http://www.securityfocus.com/bid/21932
> 
> I was hoping to find a new version
> with a fix, or at least some discussion on this topic.  Is there an effort
> I haven't seen yet that is working on a fix for this issue?
> 
>   Shlomo
> _______________________________________________
> Cicq mailing list
> Cicq-xGejAJT2w6wWP6gT/[email protected]
> http://mailman.linuxpl.org/mailman/listinfo/cicq
> Questions? Check the FAQ first: http://centericq.de/faq/

-- 
Julien LEMOINE / SpeedBlue
_______________________________________________
Cicq mailing list
Cicq-xGejAJT2w6wWP6gT/[email protected]
http://mailman.linuxpl.org/mailman/listinfo/cicq
Questions? Check the FAQ first: http://centericq.de/faq/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.