CVE-2004-0891

6 documents6 sources
Severity
10.0CRITICAL
EPSS
5.4%
top 9.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateApr 29

Description

Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDrob_flynn/gaim34 versions+33
NVDgentoo/linux1.4
NVDslackware/slackware_linux4 versions+3

Also affects: Ubuntu Linux 4.1

🔴Vulnerability Details

2
GHSA
GHSA-vxv8-px35-96ww: Buffer overflow in the MSN protocol handler for gaim 02022-04-29
CVEList
CVE-2004-0891: Buffer overflow in the MSN protocol handler for gaim 02004-10-21

📋Vendor Advisories

2
Ubuntu
gaim vulnerabilities2004-10-27
Red Hat
security flaw2004-10-19

💬Community

1
Bugzilla
CVE-2004-0891 security flaw2018-08-16