CVE-2005-0966
The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop…
Does this matter?
Lower severity and a low EPSS score (2.48%). Track it; it rarely justifies an emergency change on its own.
Description
The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 2.48% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- rob flynn/gaim
- Source
- secalert@redhat.com
References
- http://gaim.sourceforge.net/security/index.php?id=14Vendor Advisory
- http://marc.info/?l=bugtraq&m=111238715307356&w=2
- http://secunia.com/advisories/14815Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=235&release_id=317750Patch
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:071
- http://www.novell.com/linux/security/advisories/2005_36_sudo.html
- http://www.redhat.com/support/errata/RHSA-2005-365.html
- http://www.securityfocus.com/archive/1/426078/100/0/threaded
- http://www.securityfocus.com/bid/13003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19937
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19939
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9185
- http://gaim.sourceforge.net/security/index.php?id=14Vendor Advisory
- http://marc.info/?l=bugtraq&m=111238715307356&w=2
- http://secunia.com/advisories/14815Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=235&release_id=317750Patch
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:071
- http://www.novell.com/linux/security/advisories/2005_36_sudo.html
- http://www.redhat.com/support/errata/RHSA-2005-365.html
- http://www.securityfocus.com/archive/1/426078/100/0/threaded
- http://www.securityfocus.com/bid/13003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19937
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19939
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9185
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.