CVE-2002-0989: High severity Rob Flynn Gaim vulnerability
Published Sep 24, 2002
·Updated
The URL handler in the manual browser option for Gaim before 0.59.1 allows remote attackers to execute arbitrary script via shell metacharacters in a link.
Affected Software
9 affected components
Rob Flynn Gaim=0.53
Rob Flynn Gaim=0.52
Rob Flynn Gaim=0.59
Rob Flynn Gaim=0.51
Rob Flynn Gaim=0.56
Rob Flynn Gaim=0.54
Rob Flynn Gaim=0.55
Rob Flynn Gaim=0.58
Rob Flynn Gaim=0.57
Remediation
Patch Available
Patch Available
Event History
Sep 24, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0989?
CVE-2002-0989 has a severity level of medium, as it allows remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2002-0989?
To fix CVE-2002-0989, upgrade Gaim to version 0.59.1 or later.
3
Which versions of Gaim are affected by CVE-2002-0989?
CVE-2002-0989 affects Gaim versions 0.51 through 0.58.
4
Can CVE-2002-0989 lead to data loss or escalation of privileges?
Yes, CVE-2002-0989 can potentially lead to data loss or allow attackers to escalate privileges on the affected system.
5
What type of vulnerability is CVE-2002-0989?
CVE-2002-0989 is a remote code execution vulnerability caused by improper handling of URLs.