CVE-2004-0754: Integer Overflow
Published Sep 2, 2004
·Updated
Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.
Affected Software
29 affected components
Rob Flynn Gaim=0.71
Rob Flynn Gaim=0.10.3
Rob Flynn Gaim=0.61
Rob Flynn Gaim=0.53
Rob Flynn Gaim=0.73
Rob Flynn Gaim=0.60
Rob Flynn Gaim=0.69
Rob Flynn Gaim=0.52
Rob Flynn Gaim=0.72
Rob Flynn Gaim=0.65
Rob Flynn Gaim=0.59
Rob Flynn Gaim=0.62
Rob Flynn Gaim=0.74
Rob Flynn Gaim=0.51
Rob Flynn Gaim=0.56
Rob Flynn Gaim=0.54
Rob Flynn Gaim=0.55
Rob Flynn Gaim=0.68
Rob Flynn Gaim=0.67
Rob Flynn Gaim=0.10
Rob Flynn Gaim=0.59.1
Rob Flynn Gaim=0.70
Rob Flynn Gaim=0.50
Rob Flynn Gaim=0.66
Rob Flynn Gaim=0.63
Rob Flynn Gaim=0.64
Rob Flynn Gaim=0.58
Rob Flynn Gaim=0.75
Rob Flynn Gaim=0.57
Remediation
Patch Available
Patch Available
Event History
Sep 2, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0754?
CVE-2004-0754 is considered a high severity vulnerability due to its potential to cause denial of service and arbitrary code execution.
2
How do I fix CVE-2004-0754?
To fix CVE-2004-0754, you should update Gaim to version 0.82 or later, which includes a patch for this vulnerability.
3
Which versions of Gaim are affected by CVE-2004-0754?
CVE-2004-0754 affects multiple Gaim versions including 0.10, 0.61, 0.71, and others prior to 0.82.
4
What type of attack is possible with CVE-2004-0754?
CVE-2004-0754 allows remote attackers to conduct a denial of service and may enable the execution of arbitrary code.
5
Who is the vendor associated with CVE-2004-0754?
The vendor associated with CVE-2004-0754 is Rob Flynn, the developer of Gaim messaging software.