Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.
References
Link | Resource |
---|---|
http://www.kde.org/info/security/advisory-20050721-1.txt | Patch Vendor Advisory |
http://lwn.net/Articles/144724/ | Patch Vendor Advisory |
http://security.gentoo.org/glsa/glsa-200507-23.xml | Patch Vendor Advisory |
http://www.securityfocus.com/bid/14345 | Patch |
http://www.gentoo.org/security/en/glsa/glsa-200507-26.xml | |
http://secunia.com/advisories/16140 | Vendor Advisory |
http://secunia.com/advisories/16155 | Vendor Advisory |
http://secunia.com/advisories/16211 | Vendor Advisory |
http://secunia.com/advisories/16242 | Vendor Advisory |
http://www.redhat.com/support/errata/RHSA-2005-639.html | |
http://www.novell.com/linux/security/advisories/2005_19_sr.html | |
http://marc.info/?l=bugtraq&m=112198499417250&w=2 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9532 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2005-07-25 21:00
Updated : 2017-10-10 18:30
NVD link : CVE-2005-1852
Mitre link : CVE-2005-1852
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
centericq
- centericq
kadu
- kadu
ekg
- ekg
kde
- kde