|
|
|
![]() |
Vulnerability Note VU#503030Gaim fails to properly parse cookies in Yahoo web connectionsOverviewThere is a buffer overflow vulnerability in the way Gaim parses cookies for Yahoo web connections.I. DescriptionGaim is a multi-protocol instant messenger available for a number of operating systems. It supports a variety of instant messaging protocols, including the Yahoo Messenger (YMSG) protocol. There is a buffer overflow vulnerability in the yahoo_web_pending() function. This function is responsible for parsing cookies in HTTP reply headers for Yahoo web connections. When parsing the HTTP reply header, the first 1024 bytes of cookie data is copied into a 256 byte buffer without performing adequate bounds checking.II. ImpactAn unauthenticated, remote attacker could potentially execute arbitrary code with the privileges of the vulnerable process.III. SolutionUpgradeUpgrade to Gaim version 0.76 or later.
References
This vulnerability was reported by Stefan Esser of e-matters. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||