CVE-2004-0005: Buffer Overflow
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoodecode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoodecode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaimquotedpdecode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaimquotedpdecode that causes a pointer to reference memory beyond the terminating null byte.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0005?
CVE-2004-0005 has a high severity level due to potential remote code execution and denial of service risks.
How do I fix CVE-2004-0005?
To fix CVE-2004-0005, upgrade to a patched version of Gaim that addresses these buffer overflow vulnerabilities.
What versions of Gaim are affected by CVE-2004-0005?
Gaim version 0.75 is the only affected version for CVE-2004-0005.
What type of vulnerability is CVE-2004-0005?
CVE-2004-0005 is categorized as a buffer overflow vulnerability.
Can CVE-2004-0005 be exploited remotely?
Yes, CVE-2004-0005 can be exploited remotely, allowing attackers to execute arbitrary code.