7.5
CVSSv2

CVE-2014-3775

Published: 22/05/2014 Updated: 22/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

libgadu prior to 1.11.4 and 1.12.0 prior to 1.12.0-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libgadu libgadu 1.12.0

libgadu libgadu

Vendor Advisories

Pidgin could be made to crash or run programs if it received specially crafted network traffic ...
libgadu could be made to crash or run programs if it received specially crafted network traffic ...
It was discovered that malformed responses from a Gadu-Gadu file relay server could lead to denial of service or the execution of arbitrary code in applications linked to the libgadu library The oldstable distribution (squeeze) is not affected For the stable distribution (wheezy), this problem has been fixed in version 1112-1+deb7u2 For the un ...
libgadu before 1114 and 1120 before 1120-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted message ...