Vulnerability Name: | CVE-2004-0784 (CCN-17144) | ||||||||||||||||
Assigned: | 2004-08-26 | ||||||||||||||||
Published: | 2004-08-26 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0784 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:884 Fixes for gaim's vulnerabilities Source: CCN Type: Gaim Download Web page Downloads - gaim Source: CCN Type: Gaim Security Issues Web page Smiley theme installation lack of escaping Source: CONFIRM Type: Patch, Vendor Advisory http://gaim.sourceforge.net/security/?id=1 Source: CCN Type: RHSA-2004-400 gaim security update Source: CCN Type: Slackware Security Advisory SSA:2004-240-01 gaim updated again Source: CCN Type: Slackware Security Advisory SSA:2004-239-01 gaim Source: FEDORA Type: Patch, Vendor Advisory FEDORA-2004-278 Source: FEDORA Type: Patch, Vendor Advisory FEDORA-2004-279 Source: CCN Type: GLSA-200408-27 Gaim: New vulnerabilities Source: GENTOO Type: Vendor Advisory GLSA-200408-27 Source: REDHAT Type: UNKNOWN RHSA-2004:400 Source: CCN Type: BID-11056 Gaim Multiple Vulnerabilities Source: XF Type: UNKNOWN gaim-smiley-command-execution(17144) Source: XF Type: UNKNOWN gaim-smiley-command-execution(17144) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10008 Source: SUSE Type: SUSE-SA:2004:032 apache2: remote denial-of-service Source: SUSE Type: SUSE-SA:2004:033 gtk2 gdk-pixbuf: remote code execution Source: SUSE Type: SUSE-SA:2004:034 XFree86-libs xshared: remote command execution | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |