Vulnerability CVE-2005-1852


Published: 2005-07-26   Modified: 2012-02-12

Description:
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
KDE -> KDE 
KADU -> KADU 
EKG -> EKG 
Centericq -> Centericq 

 References:
http://www.securityfocus.com/bid/14345
http://www.kde.org/info/security/advisory-20050721-1.txt
http://security.gentoo.org/glsa/glsa-200507-23.xml
http://lwn.net/Articles/144724/
http://www.redhat.com/support/errata/RHSA-2005-639.html
http://www.novell.com/linux/security/advisories/2005_19_sr.html
http://www.gentoo.org/security/en/glsa/glsa-200507-26.xml
http://secunia.com/advisories/16242
http://secunia.com/advisories/16211
http://secunia.com/advisories/16155
http://secunia.com/advisories/16140
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9532
http://marc.theaimsgroup.com/?l=bugtraq&m=112198499417250&w=2

Copyright 2024, cxsecurity.com

 

Back to Top