CVE Database
/

CVE-2004-0005

Back to search

CVE-2004-0005

Published: Feb 3, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.

VendorProductVersions

n/a

n/a

affected
n/a

References

gaim-mime-decoder-oob(14944)
vdb-entry
x_refsource_XF
VU#226974
third-party-advisory
x_refsource_CERT-VN
DSA-434
vendor-advisory
x_refsource_DEBIAN
gaim-mime-decoder-bo(14942)
vdb-entry
x_refsource_XF
SuSE-SA:2004:004
vendor-advisory
x_refsource_SUSE
SSA:2004-026
vendor-advisory
x_refsource_SLACKWARE
GLSA-200401-04
vendor-advisory
x_refsource_GENTOO
1008850
vdb-entry
x_refsource_SECTRACK
3736
vdb-entry
x_refsource_OSVDB
VU#655974
third-party-advisory
x_refsource_CERT-VN
VU#190366
third-party-advisory
x_refsource_CERT-VN
CLA-2004:813
vendor-advisory
x_refsource_CONECTIVA
VU#404470
third-party-advisory
x_refsource_CERT-VN
gaim-sscanf-oob(14938)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now