CVE-2005-3891
Summary
| CVE | CVE-2005-3891 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-29 21:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache\" string that is added to the end of the buffer. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gadu-gadu | Gadu-gadu Instant Messenger | 7.20 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Gadu-Gadu Multiple Vulnerabilities and Weaknesses | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| www.osvdb.org/21016 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 'Gadu-Gadu several vulnerabilities (version <= 7.20)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Neohapsis Archives - Full Disclosure List - #0658 - [Full-disclosure] Gadu-Gadu several vulnerabilities (version <= 7.20) | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Vendor Advisory |
| Gadu-Gadu Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gadu-Gadu Multiple Remote Vulnerabilities | MITRE | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.