FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0007

This CVE name corresponds to:

Entered Topic
2004-02-12 Several remotely exploitable buffer overflows in gaim

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0007
Phase Modified(20100819)

Description

Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

References

Source Reference
BUGTRAQ 20040126 Advisory 01/2004: 12 x Gaim remote overflows
FULLDISC 20040126 Advisory 01/2004: 12 x Gaim remote overflows
MISC http://security.e-matters.de/advisories/012004.html
BUGTRAQ 20040127 Ultramagnetic Advisory #001: Multiple vulnerabilities in Gaim code
CONFIRM http://ultramagnetic.sourceforge.net/advisories/001.html
CONECTIVA CLA-2004:813
DEBIAN DSA-434
GENTOO GLSA-200401-04
MANDRAKE MDKSA-2004:006
REDHAT RHSA-2004:032
REDHAT RHSA-2004:033
SLACKWARE SSA:2004-026
SUSE SuSE-SA:2004:004
CERT-VN VU#197142
BID 9489
OSVDB 3733
OVAL oval:org.mitre.oval:def:819
OVAL oval:org.mitre.oval:def:9906
SECTRACK 1008850
XF gaim-extractinfo-bo(14946)