FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0785

This CVE name corresponds to:

Entered Topic
2004-10-25 gaim -- multiple buffer overflows

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0785
Phase Assigned(20040817)

Description

Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.

References

Source Reference
CONFIRM http://gaim.sourceforge.net/security/?id=3
CONFIRM http://gaim.sourceforge.net/security/?id=4
CONFIRM http://gaim.sourceforge.net/security/?id=5
FEDORA FEDORA-2004-278
FEDORA FEDORA-2004-279
GENTOO GLSA-200408-27
REDHAT RHSA-2004:400
BID 11056
OSVDB 9261
OSVDB 9262
OSVDB 9263
OVAL oval:org.mitre.oval:def:10907
SECTRACK 1011083
SECUNIA 12383
SECUNIA 12480
SECUNIA 12929
SECUNIA 13101
XF gaim-hostname-bo(17142)
XF gaim-rtf-bo(17141)
XF gaim-url-bo(17143)