header-logo
Suggest Exploit
vendor:
Gaim
by:
Ron
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Gaim
Affected Version From: 1.2.2001
Affected Version To: 1.2.2001
Patch Exists: NO
Related CWE:
CPE: a:gaim_project:gaim:1.2.1
Metasploit:
Other Scripts:
Platforms Tested:
2005

Gaim 1.2.1 Stack Overflow Vulnerability

This code demonstrates a stack overflow vulnerability in Gaim 1.2.1 when processing email addresses. It causes a segfault when executing the /vuln command in a conversation. If a protocol allows a 10002-character message to go through, it also segfaults the recipient. The vulnerability is due to the stack being overwritten with 'A's and the return address of the function being set to 0x41414141.

Mitigation:

Apply the patch provided by the vendor.
Source

Exploit-DB raw data: