10
CVE-2004-0891
- EPSS 6.86%
- Veröffentlicht 27.01.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:06:36
- Erkennungen
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Slackware ≫ Slackware Linux Version 9.0
Slackware ≫ Slackware Linux Version 9.1
Slackware ≫ Slackware Linux Version 10.0
Slackware ≫ Slackware Linux Version current
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ia64
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ppc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.86% | 0.932 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://gaim.sourceforge.net/security/?id=9
http://www.gentoo.org/security/en/glsa/glsa-200410-23.xml
http://www.redhat.com/support/errata/RHSA-2004-604.html
https://bugzilla.fedora.us/show_bug.cgi?id=2188
https://exchange.xforce.ibmcloud.com/vulnerabilities/17786
https://exchange.xforce.ibmcloud.com/vulnerabilities/17787
https://exchange.xforce.ibmcloud.com/vulnerabilities/17790
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11790
https://www.ubuntu.com/usn/usn-8-1/