CVE-2005-2370: Medium severity ekg ekg vulnerability
Published Jul 26, 2005
·Updated
Multiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error) on certain architectures such as SPARC via an incoming message.
Affected Software
8 affected components
ekg ekg=1.1
ekg ekg=1.3
ekg ekg=1.4
ekg ekg=1.5
ekg ekg=1.6_rc1
ekg ekg=2005-04-11
ekg ekg=2005-06-05
Rob Flynn Gaim<=1.4.0
Event History
Jul 26, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2370?
CVE-2005-2370 has a medium severity rating as it can lead to denial of service due to memory alignment errors.
2
How do I fix CVE-2005-2370?
To fix CVE-2005-2370, upgrade to a version of ekg or Gaim that is later than the vulnerable versions specified.
3
Which versions of ekg are affected by CVE-2005-2370?
CVE-2005-2370 affects ekg versions 1.1 to 1.6_rc1, including 1.3, 1.4, and 1.5.
4
Which version of Gaim is vulnerable to CVE-2005-2370?
Gaim versions up to and including 1.4.0 are vulnerable to CVE-2005-2370.
5
What kind of attacks can be executed using CVE-2005-2370?
CVE-2005-2370 allows remote attackers to send specially crafted messages that cause a bus error leading to program crashes.