Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
2004-09-28T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rob_flynn | gaim | 0.10 | Yes |
Application | rob_flynn | gaim | 0.10.3 | Yes |
Application | rob_flynn | gaim | 0.50 | Yes |
Application | rob_flynn | gaim | 0.51 | Yes |
Application | rob_flynn | gaim | 0.52 | Yes |
Application | rob_flynn | gaim | 0.53 | Yes |
Application | rob_flynn | gaim | 0.54 | Yes |
Application | rob_flynn | gaim | 0.55 | Yes |
Application | rob_flynn | gaim | 0.56 | Yes |
Application | rob_flynn | gaim | 0.57 | Yes |
Application | rob_flynn | gaim | 0.58 | Yes |
Application | rob_flynn | gaim | 0.59 | Yes |
Application | rob_flynn | gaim | 0.59.1 | Yes |
Application | rob_flynn | gaim | 0.60 | Yes |
Application | rob_flynn | gaim | 0.61 | Yes |
Application | rob_flynn | gaim | 0.62 | Yes |
Application | rob_flynn | gaim | 0.63 | Yes |
Application | rob_flynn | gaim | 0.64 | Yes |
Application | rob_flynn | gaim | 0.65 | Yes |
Application | rob_flynn | gaim | 0.66 | Yes |
Application | rob_flynn | gaim | 0.67 | Yes |
Application | rob_flynn | gaim | 0.68 | Yes |
Application | rob_flynn | gaim | 0.69 | Yes |
Application | rob_flynn | gaim | 0.70 | Yes |
Application | rob_flynn | gaim | 0.71 | Yes |
Application | rob_flynn | gaim | 0.72 | Yes |
Application | rob_flynn | gaim | 0.73 | Yes |
Application | rob_flynn | gaim | 0.74 | Yes |
Application | rob_flynn | gaim | 0.75 | Yes |
Operating System | gentoo | linux | 1.4 | Yes |
Operating System | mandrakesoft | mandrake_linux | 9.2 | Yes |
Operating System | mandrakesoft | mandrake_linux | 9.2 | Yes |
Operating System | mandrakesoft | mandrake_linux | 10.0 | Yes |
Operating System | mandrakesoft | mandrake_linux | 10.0 | Yes |