Vulnerability Name: | CVE-2005-0967 (CCN-20850) | ||||||||||||||||
Assigned: | 2005-03-28 | ||||||||||||||||
Published: | 2005-03-28 | ||||||||||||||||
Updated: | 2018-10-19 | ||||||||||||||||
Summary: | Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-0967 Source: CCN Type: Gaim Download Web page Downloads Source: CONFIRM Type: Vendor Advisory http://gaim.sourceforge.net/security/?id=15 Source: CCN Type: RHSA-2005-365 gaim security update Source: CCN Type: SA14815 Gaim Multiple Denial of Service Weaknesses Source: SECUNIA Type: Patch, Vendor Advisory 14815 Source: CCN Type: SECTRACK ID: 1013645 Gaim Can Be Crashed By Remote Users Sending Invalid Jabber File Transfer Requests Source: SECTRACK Type: Patch 1013645 Source: CCN Type: SourceForge.net Project: Gaim: Summary Source: CONFIRM Type: Exploit http://sourceforge.net/tracker/?func=detail&aid=1172115&group_id=235&atid=100235 Source: CCN Type: GLSA-200504-05 Gaim: Denial of Service issues Source: MANDRAKE Type: UNKNOWN MDKSA-2005:071 Source: SUSE Type: UNKNOWN SUSE-SA:2005:036 Source: REDHAT Type: UNKNOWN RHSA-2005:365 Source: FEDORA Type: UNKNOWN FLSA:158543 Source: BID Type: UNKNOWN 13004 Source: CCN Type: BID-13004 Gaim Jabber File Request Remote Denial Of Service Vulnerability Source: CCN Type: USN-125-1 Gaim vulnerabilities Source: XF Type: UNKNOWN gaim-jabber-file-dos(20850) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9657 Source: SUSE Type: SUSE-SA:2005:036 sudo: race condition arbitrary code execution Source: SUSE Type: SUSE-SR:2005:017 SUSE Security Summary Report | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |