CVE-2005-2102: Medium severity Rob Flynn Gaim vulnerability
Published Aug 16, 2005
·Updated
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.
Affected Software
13 affected components
Rob Flynn Gaim=1.1.4
Rob Flynn Gaim=1.0.2
Rob Flynn Gaim=1.1.2
Rob Flynn Gaim=1.0
Rob Flynn Gaim=1.0.1
Rob Flynn Gaim=1.1.0
Rob Flynn Gaim=1.2.1
Rob Flynn Gaim=1.1.3
Rob Flynn Gaim=1.2.0
Rob Flynn Gaim=1.0.3
Rob Flynn Gaim=1.0.0
Rob Flynn Gaim=1.3.0
Rob Flynn Gaim=1.1.1
Event History
Aug 16, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2102?
CVE-2005-2102 is classified as a denial of service vulnerability that allows an attacker to crash the Gaim application.
2
How do I fix CVE-2005-2102?
To fix CVE-2005-2102, upgrade Gaim to version 1.5.0 or later, which addresses this vulnerability.
3
Which versions of Gaim are affected by CVE-2005-2102?
CVE-2005-2102 affects Gaim versions 1.0.0 through 1.4.x.
4
Can CVE-2005-2102 be exploited remotely?
Yes, CVE-2005-2102 can be exploited remotely by sending a specially crafted filename with invalid UTF-8 characters.
5
Is there a workaround for CVE-2005-2102?
As a temporary workaround for CVE-2005-2102, avoid opening files with unknown or suspicious filenames while using affected versions of Gaim.