Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
BID:11998
Info
Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
| Bugtraq ID: | 11998 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2004 12:00AM |
| Updated: | Dec 17 2004 12:00AM |
| Credit: | Jaroslaw Sajko <[email protected]> an Blazej Miga <[email protected]> are credited with the discovery of these issues. |
| Vulnerable: |
Gadu-Gadu Instant Messenger 6.0 build 155 Gadu-Gadu Instant Messenger 6.0 build 154 Gadu-Gadu Instant Messenger 6.0 build 153 Gadu-Gadu Instant Messenger 6.0 build 152 Gadu-Gadu Instant Messenger 6.0 build 151 Gadu-Gadu Instant Messenger 6.0 build 150 Gadu-Gadu Instant Messenger 6.0 build 149 Gadu-Gadu Instant Messenger 6.0 |
| Not Vulnerable: |
Gadu-Gadu Instant Messenger 6.0 build 156 |
Discussion
Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
Multiple remote vulnerabilities reportedly affect Gadu-Gadu instant messenger. It supports the DCC (Direct Client Connection) protocol, facilitating the transfer of files and messages between users.
The input validation issue is an HTML injection vulnerability in the instant messaging system. It is worth noting that this issue, although not exactly the same, resembles closely the HTML injection issue outlined in BID 11899 (Gadu-Gadu Multiple Remote Vulnerabilities). The denial of service vulnerability is due to a bug in the image handling code of the affected application.
An attacker may leverage these issues to carry out HTML injection attacks, potentially stealing sensitive information, and to carry out denial of service attacks, denying legitimate users of access to the affected software.
Multiple remote vulnerabilities reportedly affect Gadu-Gadu instant messenger. It supports the DCC (Direct Client Connection) protocol, facilitating the transfer of files and messages between users.
The input validation issue is an HTML injection vulnerability in the instant messaging system. It is worth noting that this issue, although not exactly the same, resembles closely the HTML injection issue outlined in BID 11899 (Gadu-Gadu Multiple Remote Vulnerabilities). The denial of service vulnerability is due to a bug in the image handling code of the affected application.
An attacker may leverage these issues to carry out HTML injection attacks, potentially stealing sensitive information, and to carry out denial of service attacks, denying legitimate users of access to the affected software.
Exploit / POC
Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
No exploit is required to leverage these issues.
The following proof of concept, when embedded into a message, will reportedly trigger the HTML injection issue:
www.po"style=background-image:url(javascript:document.write('%3cscript%3ealert%28%22you%20are%20owned!%22%29%3c%2fscript%3e'));".pl
No exploit is required to leverage these issues.
The following proof of concept, when embedded into a message, will reportedly trigger the HTML injection issue:
www.po"style=background-image:url(javascript:document.write('%3cscript%3ealert%28%22you%20are%20owned!%22%29%3c%2fscript%3e'));".pl
Solution / Fix
Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
Solution:
Reportedly this issue has been resolved in version 6.0 build 156. Users are advised to contact the vendor for more information on obtaining the fixed packages.
Solution:
Reportedly this issue has been resolved in version 6.0 build 156. Users are advised to contact the vendor for more information on obtaining the fixed packages.
References
Gadu-Gadu Multiple Remote Input Validation And Denial Of Service Vulnerabilities
References:
References:
- Vendor Homepage (Gadu-Gadu)