CVE-2008-6393

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:psi-im:psi:*:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.9:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:psi-im:psi:0.11:*:*:*:*:*:*:*
cpe:2.3:a:jabber:jabber_client:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-03-03 16:30

Updated : 2024-02-04 17:33


NVD link : CVE-2008-6393

Mitre link : CVE-2008-6393

CVE.ORG link : CVE-2008-6393


JSON object : View

Products Affected

jabber

  • jabber_client

psi-im

  • psi
CWE
CWE-189

Numeric Errors