First published: Fri Nov 18 2005(Updated: )
Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Talk | =1.0.0.68 | |
Google Talk | =1.0.0.67 | |
Google Talk | =1.0.0.72 | |
Google Talk | =1.0.0.70 | |
Google Talk | =1.0.0.75 | |
Google Talk | =1.0.0.66 | |
Google Talk | <=1.0.0.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3678 affects Google Talk versions 1.0.0.66 to 1.0.0.75 and the versions preceding 1.0.0.64.
CVE-2005-3678 allows remote attackers to cause a denial of service by sending an email with a blank sender.
The impact of CVE-2005-3678 is a denial of service, which prevents legitimate users from connecting to Google Talk.
To mitigate CVE-2005-3678, users should disable email notifications in Google Talk or upgrade to a patched version.
CVE-2005-3678 is classified as a denial of service vulnerability, which can significantly disrupt service but is not considered a critical security risk.