First published: Fri Dec 31 2004(Updated: )
Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to allocate memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gaim | =0.10 | |
Gaim | =0.10.3 | |
Gaim | =0.50 | |
Gaim | =0.51 | |
Gaim | =0.52 | |
Gaim | =0.53 | |
Gaim | =0.54 | |
Gaim | =0.55 | |
Gaim | =0.56 | |
Gaim | =0.57 | |
Gaim | =0.58 | |
Gaim | =0.59 | |
Gaim | =0.59.1 | |
Gaim | =0.60 | |
Gaim | =0.61 | |
Gaim | =0.62 | |
Gaim | =0.63 | |
Gaim | =0.64 | |
Gaim | =0.65 | |
Gaim | =0.66 | |
Gaim | =0.67 | |
Gaim | =0.68 | |
Gaim | =0.69 | |
Gaim | =0.70 | |
Gaim | =0.71 | |
Gaim | =0.72 | |
Gaim | =0.73 | |
Gaim | =0.74 | |
Gaim | =0.75 | |
Gaim | =0.76 | |
Gaim | =0.77 | |
Gaim | =0.78 | |
Gaim | =0.79 | |
Gaim | =0.80 | |
Gaim | =0.81 | |
Gaim | =0.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2589 is considered a denial of service vulnerability that can lead to application crashes.
To fix CVE-2004-2589, upgrade Gaim to version 0.82 or later where the vulnerability has been addressed.
CVE-2004-2589 affects Gaim versions before 0.82, specifically from 0.10 to 0.81.
CVE-2004-2589 can be exploited by sending a specially crafted long HTTP Content-Length header to the Gaim application.
Yes, upgrading to Gaim version 0.82 or later serves as a patch for CVE-2004-2589.