FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0754

This CVE name corresponds to:

Entered Topic
2004-10-25 gaim -- heap overflow exploitable by malicious GroupWise server

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0754
Phase Assigned(20040726)

Description

Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.

References

Source Reference
CONFIRM http://gaim.sourceforge.net/security/?id=2
FEDORA FEDORA-2004-278
FEDORA FEDORA-2004-279
GENTOO GLSA-200408-27
REDHAT RHSA-2004:400
BID 11056
OSVDB 9260
OVAL oval:org.mitre.oval:def:10220
SECTRACK 1011083
SECUNIA 12383
SECUNIA 12480
SECUNIA 13101
XF gaim-groupware-integer-overflow(17140)