gajim jabber client multiple security vulnerabilities
Description:Unescaped shell characters, symbolic links vulnerability, SQL injections.
Affected:GAJIM : gajim 0.15
CVE:CVE-2012-2093 (src/common/ in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.)
 CVE-2012-2086 (SQL injection vulnerability in the get_last_conversation_lines function in common/ in Gajim before 0.15 allows remote attackers to execute arbitrary SQL commands via the jig parameter.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 2453-1] gajim security update (19.04.2012)

