9.8

CVE-2004-0005

Exploit
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gaim ProjectGaim Version0.75
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.21% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
Broken Link
http://marc.info/?l=bugtraq&m=107513690306318&w=2
Exploit
Mailing List
http://security.e-matters.de/advisories/012004.html
Patch
Vendor Advisory
Broken Link
http://www.debian.org/security/2004/dsa-434
Patch
Vendor Advisory
Broken Link
http://www.kb.cert.org/vuls/id/190366
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/226974
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/404470
Third Party Advisory
US Government Resource
http://www.kb.cert.org/vuls/id/655974
Third Party Advisory
US Government Resource
http://www.novell.com/linux/security/advisories/2004_04_gaim.html
Broken Link
http://www.osvdb.org/3736
Broken Link
http://www.securitytracker.com/id?1008850
Third Party Advisory
Broken Link
VDB Entry
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
Patch
Mailing List
https://exchange.xforce.ibmcloud.com/vulnerabilities/14935
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14938
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14942
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14944
Third Party Advisory
VDB Entry
https://security.gentoo.org/glsa/200401-04
Third Party Advisory