CVE-2004-0891

Publication date 27 January 2005

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.

Status

Package Ubuntu Release Status
gaim 7.04 feisty
Fixed 1.5.0+1.5.1cvs20051015-1ubuntu10
6.10 edgy
Fixed 1.5.0+1.5.1cvs20051015-1ubuntu10
6.06 LTS dapper
Fixed 1.5.0+1.5.1cvs20051015-1ubuntu10

References

Related Ubuntu Security Notices (USN)

    • USN-8-1
    • gaim vulnerabilities
    • 27 October 2004

Other references