HIGH · 7.8

CVE-2005-3891

Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "...

Vulnerability Description

Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache\" string that is added to the end of the buffer.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
Gadu-GaduGadu-Gadu Instant Messenger7.20

References

FAQ

What is CVE-2005-3891?

CVE-2005-3891 is a vulnerability with a CVSS score of 7.8 (HIGH). Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "...

How severe is CVE-2005-3891?

CVE-2005-3891 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3891?

Check the references section above for vendor advisories and patch information. Affected products include: Gadu-Gadu Gadu-Gadu Instant Messenger.