PT-2004-1857 · Gaim · Gaim

Published

2004-09-02

·

Updated

2017-10-11

·

CVE-2004-0785

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Gaim versions prior to 0.82
Description The issue is related to multiple buffer overflows that can be triggered by remote attackers, potentially leading to a denial of service and possibly the execution of arbitrary code. This can occur through various means, including Rich Text Format (RTF) messages, a long hostname for the local system as obtained from DNS, or a long URL that is not properly handled by the URL decoder.
Recommendations For versions prior to 0.82, update to version 0.82 or later to resolve the issue. As a temporary workaround, consider restricting the handling of RTF messages and limiting the length of hostnames and URLs to prevent potential exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0785

Affected Products

Gaim