Back to search
CVE-2008-6393
Published: Mar 3, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
34259
third-party-advisory
x_refsource_SECUNIA
http://bugs.gentoo.org/show_bug.cgi?id=252830
x_refsource_CONFIRM
34301
third-party-advisory
x_refsource_SECUNIA
7555
exploit
x_refsource_EXPLOIT-DB
20081223 [ISecAuditors Security Advisories] PSI remote integer overflow DoS
mailing-list
x_refsource_BUGTRAQ
SUSE-SR:2009:006
vendor-advisory
x_refsource_SUSE
FEDORA-2009-2285
vendor-advisory
x_refsource_FEDORA
[oss-security] 20090225 CVE request: Psi <0.12.1 DoS
mailing-list
x_refsource_MLIST
http://sourceforge.net/project/shownotes.php?release_id=658912
x_refsource_CONFIRM
33311
third-party-advisory
x_refsource_SECUNIA
FEDORA-2009-2295
vendor-advisory
x_refsource_FEDORA
DSA-1741
vendor-advisory
x_refsource_DEBIAN
34119
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now