Vulnerability Description
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rob Flynn | Gaim | <= 0.75 |
| Ultramagnetic | Ultramagnetic | <= 0.81 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
- ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
- http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
- http://marc.info/?l=bugtraq&m=107513690306318&w=2
- http://marc.info/?l=bugtraq&m=107522432613022&w=2
- http://security.e-matters.de/advisories/012004.htmlPatchVendor Advisory
- http://security.gentoo.org/glsa/glsa-200401-04.xmlVendor Advisory
- http://ultramagnetic.sourceforge.net/advisories/001.htmlPatchVendor Advisory
- http://www.debian.org/security/2004/dsa-434
- http://www.kb.cert.org/vuls/id/297198US Government Resource
- http://www.kb.cert.org/vuls/id/371382US Government Resource
- http://www.kb.cert.org/vuls/id/444158US Government Resource
- http://www.kb.cert.org/vuls/id/503030US Government Resource
- http://www.kb.cert.org/vuls/id/527142US Government Resource
FAQ
What is CVE-2004-0006?
CVE-2004-0006 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo we...
How severe is CVE-2004-0006?
CVE-2004-0006 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0006?
Check the references section above for vendor advisories and patch information. Affected products include: Rob Flynn Gaim, Ultramagnetic Ultramagnetic.