FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0967

This CVE name corresponds to:

Entered Topic
2005-04-10 gaim -- jabber remote crash

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0967
Phase Assigned(20050405)

Description

Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.

References

Source Reference
CONFIRM http://gaim.sourceforge.net/security/?id=15
CONFIRM http://sourceforge.net/tracker/?func=detail&aid=1172115&group_id=235&atid=100235
FEDORA FLSA:158543
MANDRAKE MDKSA-2005:071
REDHAT RHSA-2005:365
SUSE SUSE-SA:2005:036
BID 13004
OVAL oval:org.mitre.oval:def:9657
SECTRACK 1013645
SECUNIA 14815