CVE-2005-2370

NameCVE-2005-2370
DescriptionMultiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error) on certain architectures such as SPARC via an incoming message.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1318-1, DSA-769-1, DSA-813-1, DTSA-2-1, DTSA-5-1
NVD severitymedium (attack range: remote)
Debian Bugs323185
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ekg (PTS)squeeze1:1.8~rc1-1fixed
wheezy1:1.9~pre+r2854-1fixed
jessie, sid1:1.9~pre+r2855-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
centericqsource(unstable)4.20.0-9low323185
centericqsourceetch4.20.0-8etch1mediumDTSA-2-1
centericqsourcesarge4.20.0-1sarge2mediumDSA-813-1
centericqsourcewoody(not affected)DSA-813-1
ekgsource(unstable)1:1.5+20050712+1.6rc2-1low
ekgsourceetch1:1.7~rc2-1etch1mediumDSA-1318-1
ekgsourcesarge1:1.5+20050411-7mediumDSA-1318-1
gaimsource(unstable)1:1.4.0-5low
gaimsourceetch1:1.4.0-5etch2highDTSA-5-1
gaimsourcesarge1:1.2.1-1.4lowDSA-769-1

Search for package or bug name: Reporting problems