FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0500

This CVE name corresponds to:

Entered Topic
2004-08-12 gaim remotely exploitable vulnerabilities in MSN component

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0500
Phase Assigned(20040527)

Description

Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.

References

Source Reference
FEDORA FEDORA-2004-278
FEDORA FEDORA-2004-279
GENTOO GLSA-200408-12
GENTOO GLSA-200408-27
MANDRAKE MDKSA-2004:081
REDHAT RHSA-2004:400
SUSE SUSE-SA:2004:025
CONFIRM http://gaim.sourceforge.net/security/?id=0
BID 10865
OVAL oval:org.mitre.oval:def:9429
XF gaim-msn-bo(16920)