PT-2004-1237 · Yahoo · Yahoo
Publicado
2004-01-29
·
Atualizado
2017-10-11
·
CVE-2004-0006
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gaim versions 0.75 and earlier
Ultramagnetic versions prior to 0.81
Description
The issue concerns multiple buffer overflows that can be triggered by remote attackers, potentially leading to a denial of service or the execution of arbitrary code. The overflows can occur through various means, including cookies in a Yahoo web connection, a long name parameter in the Yahoo login web page, a long value parameter in the Yahoo login page, a YMSG packet, the URL parser, and HTTP proxy connect.
Recommendations
For Gaim versions 0.75 and earlier, update to a version later than 0.75 to resolve the issue.
For Ultramagnetic versions prior to 0.81, update to version 0.81 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Yahoo