CVE Database
/

CVE-2008-6393

Back to search

CVE-2008-6393

Published: Mar 3, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

34259
third-party-advisory
x_refsource_SECUNIA
34301
third-party-advisory
x_refsource_SECUNIA
7555
exploit
x_refsource_EXPLOIT-DB
SUSE-SR:2009:006
vendor-advisory
x_refsource_SUSE
FEDORA-2009-2285
vendor-advisory
x_refsource_FEDORA
33311
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-2295
vendor-advisory
x_refsource_FEDORA
DSA-1741
vendor-advisory
x_refsource_DEBIAN
34119
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now