FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0965

This CVE name corresponds to:

Entered Topic
2005-04-10 gaim -- remote DoS on receiving malformed HTML

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0965
Phase Assigned(20050404)

Description

The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.

References

Source Reference
BUGTRAQ 20050401 multiple remote denial of service vulnerabilities in Gaim
CONFIRM http://gaim.sourceforge.net/security/index.php?id=13
FEDORA FLSA:158543
MANDRAKE MDKSA-2005:071
REDHAT RHSA-2005:365
SUSE SUSE-SA:2005:036
BID 12999
OVAL oval:org.mitre.oval:def:11292
SECUNIA 14815