PT-2004-1857 · Gaim · Gaim
Publicado
2004-09-02
·
Atualizado
2017-10-11
·
CVE-2004-0785
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Gaim versions prior to 0.82
Description
The issue is related to multiple buffer overflows that can be triggered by remote attackers, potentially leading to a denial of service and possibly the execution of arbitrary code. This can occur through various means, including Rich Text Format (RTF) messages, a long hostname for the local system as obtained from DNS, or a long URL that is not properly handled by the URL decoder.
Recommendations
For versions prior to 0.82, update to version 0.82 or later to resolve the issue. As a temporary workaround, consider restricting the handling of RTF messages and limiting the length of hostnames and URLs to prevent potential exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gaim