CVE-2005-0966

8 documents6 sources
Severity
6.4MEDIUM
EPSS
2.9%
top 13.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

NVDrob_flynn/gaim1.2.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gfx6-95r4-jp6g: The IRC protocol plugin in Gaim 12022-05-01
CVEList
CVE-2005-0966: The IRC protocol plugin in Gaim 12005-04-04

📋Vendor Advisories

2
Ubuntu
Gaim vulnerabilities2005-04-05
Red Hat
security flaw2005-04-01

💬Community

2
Bugzilla
CVE-2005-0966 security flaw2018-08-16
Bugzilla
CAN-2005-0208,0472,0473,0965,0966,0967 gaim security issues2005-03-10