First published: Tue Aug 16 2005(Updated: )
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gaim | =1.1.4 | |
Gaim | =1.0.2 | |
Gaim | =1.1.2 | |
Gaim | =1.0 | |
Gaim | =1.0.1 | |
Gaim | =1.1.0 | |
Gaim | =1.2.1 | |
Gaim | =1.1.3 | |
Gaim | =1.2.0 | |
Gaim | =1.0.3 | |
Gaim | =1.0.0 | |
Gaim | =1.3.0 | |
Gaim | =1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2102 is classified as a denial of service vulnerability that allows an attacker to crash the Gaim application.
To fix CVE-2005-2102, upgrade Gaim to version 1.5.0 or later, which addresses this vulnerability.
CVE-2005-2102 affects Gaim versions 1.0.0 through 1.4.x.
Yes, CVE-2005-2102 can be exploited remotely by sending a specially crafted filename with invalid UTF-8 characters.
As a temporary workaround for CVE-2005-2102, avoid opening files with unknown or suspicious filenames while using affected versions of Gaim.