|
|
|
![]() |
Vulnerability Note VU#655974Gaim contains a buffer overflow vulnerability in the yahoo_decode() functionOverviewThere is a buffer overflow vulnerability in the Gaim yahoo_decode() function, which could cause a pointer to reference memory beyond the terminating null byte.I. DescriptionGaim is a multi-protocol instant messenger available for a number of operating systems. It supports a variety of instant messaging protocols, including the Yahoo Messenger (YMSG) protocol. There is a buffer overflow vulnerability in the yahoo_decode() function. This function fails to properly allocate memory for octal values, which could result in a pointer referencing a memory location beyond the terminating null byte.II. ImpactAn unauthenticated, remote attacker may cause a denial of service or potentially execute code of the attacker's choice.III. SolutionUpgradeUpgrade to Gaim version 0.76 or later.
References
This vulnerability was publicly reported by Stefan Esser of e-matters. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||