Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2005-1852


Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.


Published

2005-07-26T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-189

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ekg ekg 1.0 Yes
Application ekg ekg 1.0_rc2 Yes
Application ekg ekg 1.0_rc3 Yes
Application ekg ekg 1.1 Yes
Application ekg ekg 1.1_rc1 Yes
Application ekg ekg 1.1_rc2 Yes
Application ekg ekg 1.3 Yes
Application ekg ekg 1.4 Yes
Application ekg ekg 1.5 Yes
Application ekg ekg 1.5_rc1 Yes
Application ekg ekg 1.5_rc2 Yes
Operating System kde kde 3.2.3 Yes
Operating System kde kde 3.3 Yes
Operating System kde kde 3.3.1 Yes
Operating System kde kde 3.3.2 Yes
Operating System kde kde 3.4 Yes
Operating System kde kde 3.4.0 Yes
Operating System kde kde 3.4.1 Yes
Application centericq centericq * Yes
Application kadu kadu * Yes

References