CVE-2004-0891: Buffer Overflow
Published Oct 21, 2004
·Updated
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
Affected Software
46 affected componentsFixes available
ubuntu/gaim<1.5.0+1.5.1
1.5.0+1.5.1
ubuntu/gaim<1.5.0+1.5.1
1.5.0+1.5.1
ubuntu/gaim<1.5.0+1.5.1
1.5.0+1.5.1
debian/gaim
Rob Flynn Gaim=0.71
Rob Flynn Gaim=0.10.3
Rob Flynn Gaim=0.61
Rob Flynn Gaim=0.82.1
Rob Flynn Gaim=0.53
Rob Flynn Gaim=0.73
Rob Flynn Gaim=1.0
Rob Flynn Gaim=0.60
Rob Flynn Gaim=1.0.1
Rob Flynn Gaim=0.69
Rob Flynn Gaim=0.52
Rob Flynn Gaim=0.72
Rob Flynn Gaim=0.65
Rob Flynn Gaim=0.59
Rob Flynn Gaim=0.62
Rob Flynn Gaim=0.78
Rob Flynn Gaim=0.74
Rob Flynn Gaim=0.51
Rob Flynn Gaim=0.56
Rob Flynn Gaim=0.54
Rob Flynn Gaim=0.55
Rob Flynn Gaim=0.82
Rob Flynn Gaim=0.68
Rob Flynn Gaim=0.67
Rob Flynn Gaim=0.10
Rob Flynn Gaim=0.59.1
Rob Flynn Gaim=0.70
Rob Flynn Gaim=0.50
Rob Flynn Gaim=0.66
Rob Flynn Gaim=0.63
Rob Flynn Gaim=0.64
Rob Flynn Gaim=0.58
Rob Flynn Gaim=0.75
Rob Flynn Gaim=0.57
Slackware Slackware Linux=9.0
Slackware Slackware Linux=10.0
Ubuntu Ubuntu Linux=4.1
Slackware Slackware Linux=9.1
Slackware Slackware Linux=current
Gentoo Linux=1.4
Ubuntu Ubuntu Linux=4.1
Gentoo Linux
Event History
Oct 21, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 13, 2024
Data Sourced
via Launchpad·04:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0891?
The severity of CVE-2004-0891 is high due to its potential to cause application crashes and arbitrary code execution.
2
How do I fix CVE-2004-0891?
To fix CVE-2004-0891, upgrade to gaim version 1.5.0 or later.
3
What software is affected by CVE-2004-0891?
CVE-2004-0891 affects gaim versions 0.79 through 1.0.1, among others.
4
Can CVE-2004-0891 lead to a denial of service?
Yes, CVE-2004-0891 can lead to a denial of service by crashing the application.
5
Is CVE-2004-0891 still a risk with updated software?
CVE-2004-0891 should no longer pose a risk if the software has been updated to the fixed version.