Mandriva Security http://www.mandriva.com/en/security/advisories Mandriva security advisories en-us MDVA-2009:125: kde4-style-iaora http://www.mandriva.com/en/security/advisories?name=MDVA-2009:125 This update of the IaOra theme for KDE4 contains several bugfixes,<br /> including:<br /> - check boxes are not visible (#50260)<br /> - arabic text overlaps in KDE 4.2 menus (#50993) MDVA-2009:124: msec http://www.mandriva.com/en/security/advisories?name=MDVA-2009:124 This update fixes a number of issues with msec shipped with Mandriva<br /> Linux 2009.1:<br /> - Msec would send an error message when desktop notification support<br /> (NOTIFY_WARN) was not found in the security configuration file<br /> (#51364, #51464)<br /> - In some locales, msec would show an error message or incorrectly<br /> translated messages when running in console (#50869)<br /> This update also adds updated translation files for msec. MDVA-2009:123: kde4 http://www.mandriva.com/en/security/advisories?name=MDVA-2009:123 Mandriva Linux 2009 Spring was released with KDE4 version 4.2.2.<br /> <br /> This update upgrades KDE4 in Mandriva Linux 2009 Spring to version<br /> 4.2.4, which brings many bugfixes and overall improvements. MDVSA-2009:147: pidgin http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:147 Security vulnerabilities has been identified and fixed in pidgin:<br /> <br /> Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin<br /> (formerly Gaim) before 2.5.6 allows remote authenticated users to<br /> execute arbitrary code via vectors involving an outbound XMPP file<br /> transfer. NOTE: some of these details are obtained from third party<br /> information (CVE-2009-1373).<br /> <br /> Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim)<br /> before 2.5.6 allows remote attackers to cause a denial of service<br /> (application crash) via a QQ packet (CVE-2009-1374).<br /> <br /> The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before<br /> 2.5.6 does not properly maintain a certain buffer, which allows<br /> remote attackers to cause a denial of service (memory corruption<br /> and application crash) via vectors involving the (1) XMPP or (2)<br /> Sametime protocol (CVE-2009-1375).<br /> <br /> Multiple integer overflows in the msn_slplink_process_msg functions in<br /> the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and<br /> (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim)<br /> before 2.5.6 on 32-bit platforms allow remote attackers to execute<br /> arbitrary code via a malformed SLP message with a crafted offset<br /> value, leading to buffer overflows. NOTE: this issue exists because<br /> of an incomplete fix for CVE-2008-2927 (CVE-2009-1376).<br /> <br /> This update provides pidgin 2.5.8, which is not vulnerable to these<br /> issues. MDVA-2009:122-1: timezone http://www.mandriva.com/en/security/advisories?name=MDVA-2009:122-1 Updated timezone packages are being provided for older Mandriva Linux<br /> systems that do not contain new Daylight Savings Time information<br /> and Time Zone information for some locations. These updated packages<br /> contain the new information.<br /> <br /> Update:<br /> <br /> Packages for MNF2/CS3/CS4 is now also provided. MDVSA-2009:146: imap http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:146 Security vulnerabilities has been identified and fixed in University<br /> of Washington IMAP Toolkit:<br /> <br /> Multiple stack-based buffer overflows in (1) University of Washington<br /> IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine<br /> 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain<br /> privileges by specifying a long folder extension argument on the<br /> command line to the tmail or dmail program; and (b) remote attackers to<br /> execute arbitrary code by sending e-mail to a destination mailbox name<br /> composed of a username and '+' character followed by a long string,<br /> processed by the tmail or possibly dmail program (CVE-2008-5005).<br /> <br /> smtp.c in the c-client library in University of Washington IMAP Toolkit<br /> 2007b allows remote SMTP servers to cause a denial of service (NULL<br /> pointer dereference and application crash) by responding to the QUIT<br /> command with a close of the TCP connection instead of the expected<br /> 221 response code (CVE-2008-5006).<br /> <br /> Off-by-one error in the rfc822_output_char function in the RFC822BUFFER<br /> routines in the University of Washington (UW) c-client library, as<br /> used by the UW IMAP toolkit before imap-2007e and other applications,<br /> allows context-dependent attackers to cause a denial of service (crash)<br /> via an e-mail message that triggers a buffer overflow (CVE-2008-5514).<br /> <br /> The updated packages have been patched to prevent this. Note that the<br /> software was renamed to c-client starting from Mandriva Linux 2009.0<br /> and only provides the shared c-client library for the imap functions<br /> in PHP. MDVA-2009:122: timezone http://www.mandriva.com/en/security/advisories?name=MDVA-2009:122 Updated timezone packages are being provided for older Mandriva Linux<br /> systems that do not contain new Daylight Savings Time information<br /> and Time Zone information for some locations. These updated packages<br /> contain the new information. MDVSA-2009:145: php http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:145 A vulnerability has been found and corrected in PHP:<br /> <br /> - Fixed upstream bug #48378 (exif_read_data() segfaults on certain<br /> corrupted .jpeg files).<br /> <br /> The updated packages have been patched to correct these issues. MDVSA-2009:144: ghostscript http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:144 Multiple security vulnerabilities has been identified and fixed<br /> in ghostscript:<br /> <br /> Multiple integer overflows in JasPer 1.900.1 might allow<br /> context-dependent attackers to have an unknown impact via a crafted<br /> image file, related to integer multiplication for memory allocation<br /> (CVE-2008-3520).<br /> <br /> Buffer overflow in the jas_stream_printf function in<br /> libjasper/base/jas_stream.c in JasPer 1.900.1 might allow<br /> context-dependent attackers to have an unknown impact via<br /> vectors related to the mif_hdr_put function and use of vsprintf<br /> (CVE-2008-3522).<br /> <br /> Previousely the ghostscript packages were statically built against<br /> a bundled and private copy of the jasper library. This update makes<br /> ghostscript link against the shared system jasper library which<br /> makes it easier to address presumptive future security issues in the<br /> jasper library. MDVSA-2009:143: netpbm http://www.mandriva.com/en/security/advisories?name=MDVSA-2009:143 Multiple security vulnerabilities has been identified and fixed<br /> in netpbm:<br /> <br /> Multiple integer overflows in JasPer 1.900.1 might allow<br /> context-dependent attackers to have an unknown impact via a crafted<br /> image file, related to integer multiplication for memory allocation<br /> (CVE-2008-3520).<br /> <br /> Buffer overflow in the jas_stream_printf function in<br /> libjasper/base/jas_stream.c in JasPer 1.900.1 might allow<br /> context-dependent attackers to have an unknown impact via<br /> vectors related to the mif_hdr_put function and use of vsprintf<br /> (CVE-2008-3522).<br /> <br /> The updated packages have been patched to prevent this.