9.8
CVSSv3

CVE-2005-2103

Published: 16/08/2005 Updated: 02/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the AIM and ICQ module in Gaim prior to 1.5.0 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.

Vulnerable Product Search on Vulmon Subscribe to Product

gaim project gaim

Vendor Advisories

Daniel Atallah discovered a Denial of Service vulnerability in the file transfer handler of OSCAR (the module that handles various instant messaging protocols like ICQ) A remote attacker could crash the Gaim client of an user by attempting to send him a file with a name that contains invalid UTF-8 characters (CAN-2005-2102) ...
Synopsis gaim security update Type/Severity Security Advisory: Critical Topic An updated gaim package that fixes a buffer overflow security issue is nowavailableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Gaim is an Intern ...
Synopsis gaim security update Type/Severity Security Advisory: Critical Topic An updated gaim package that fixes multiple security issues is now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Gaim is an Internet Mess ...

Exploits

source: wwwsecurityfocuscom/bid/14531/info Gaim is prone to multiple vulnerabilities affecting the AIM and ICQ protocols These issues may allow remote attackers to trigger a buffer overflow or a denial-of-service condition All versions of Gaim 1x are considered vulnerable at the moment %n %n %n %n %n %n %n %n %n %n %n %n %n %n %n % ...