7.5
CVSSv2

CVE-2005-1261

Published: 11/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the URL parsing function in Gaim prior to 1.3.0 allows remote malicious users to execute arbitrary code via an instant message (IM) with a large URL.

Vulnerable Product Search on Vulmon Subscribe to Product

rob flynn gaim 0.50

rob flynn gaim 0.51

rob flynn gaim 0.52

rob flynn gaim 0.59

rob flynn gaim 0.59.1

rob flynn gaim 0.66

rob flynn gaim 0.67

rob flynn gaim 0.74

rob flynn gaim 0.75

rob flynn gaim 0.76

rob flynn gaim 0.82.1

rob flynn gaim 1.0.0

rob flynn gaim 1.1.3

rob flynn gaim 1.1.4

rob flynn gaim 0.55

rob flynn gaim 0.56

rob flynn gaim 0.62

rob flynn gaim 0.63

rob flynn gaim 0.70

rob flynn gaim 0.71

rob flynn gaim 0.79

rob flynn gaim 0.80

rob flynn gaim 1.0.3

rob flynn gaim 1.1.0

rob flynn gaim 0.10

rob flynn gaim 0.10.3

rob flynn gaim 0.57

rob flynn gaim 0.58

rob flynn gaim 0.64

rob flynn gaim 0.65

rob flynn gaim 0.72

rob flynn gaim 0.73

rob flynn gaim 0.81

rob flynn gaim 0.82

rob flynn gaim 1.1.1

rob flynn gaim 1.1.2

rob flynn gaim 0.53

rob flynn gaim 0.54

rob flynn gaim 0.60

rob flynn gaim 0.61

rob flynn gaim 0.68

rob flynn gaim 0.69

rob flynn gaim 0.77

rob flynn gaim 0.78

rob flynn gaim 1.0.1

rob flynn gaim 1.0.2

rob flynn gaim 1.2.0

rob flynn gaim 1.2.1

Vendor Advisories

Marco Alvarez found a Denial of Service vulnerability in the Jabber protocol handler A remote attacker could exploit this to crash Gaim by sending specially crafted file transfers to the user (CAN-2005-0967) ...
Synopsis gaim security update Type/Severity Security Advisory: Critical Topic An updated gaim package that fixes two security issues is now availableThis update has been rated as having critical security impact by the Red HatSecurity Response Team Description The Gaim application is a mul ...
Synopsis gaim security update Type/Severity Security Advisory: Critical Topic An updated gaim package that fixes security issues is now available for RedHat Enterprise Linux 21This update has been rated as having critical security impact by the RedHat Security Response Team Description T ...

Exploits

// Written by Ron <iago@valhallalegendscom> // Friday, May 13, 2005 // // This is a very weak demonstration of Gaim 121's stack overflow vulnerability // when processing email addresses What this basically does is segfault you when you // do a /vuln command in a conversation, and, if you're using a protocol that allows // a 10002-charact ...