CVE-2008-4776Improper Restriction of Operations within the Bounds of a Memory Buffer in Libgadu

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateMay 17

Description

libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/libgadu< libgadu 1:1.8.0+r592-3 (bookworm)
Debianlibgadu/libgadu< 1:1.8.0+r592-3+3

🔴Vulnerability Details

2
GHSA
GHSA-3p9w-wq67-w93f: libgadu before 12022-05-17
OSV
CVE-2008-4776: libgadu before 12008-10-28

📋Vendor Advisories

3
Ubuntu
Gadu vulnerability2008-12-17
Debian
CVE-2008-4776: libgadu - libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) ...2008
Red Hat
libgadu: contact description buffer over-read vulnerability

💬Community

1
Bugzilla
CVE-2008-4776 libgadu: contact description buffer over-read vulnerability2008-10-28