Package: amsn
Version: 0.98.1-1
Severity: important
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published quite a while ago for amsn.  Please check whether these
issues still exist.  If so, you may want to issue proposed-updates for
the stable releases.

CVE-2006-0138[0]:
| aMSN (aka Alvaro's Messenger) allows remote attackers to cause a
| denial of service (client hang and termination of client's
| instant-messaging session) by repeatedly sending crafted data to the
| default file-transfer port (TCP 6891).

CVE-2007-2195[1]:
| aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers
| to cause a denial of service (application crash) by sending invalid
| data to TCP port 31337.

If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0138
    http://security-tracker.debian.org/tracker/CVE-2006-0138
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2195
    http://security-tracker.debian.org/tracker/CVE-2007-2195



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to