decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gaim-encryption | Gaim-encryption | 1.13 | 1.13 |
Gaim-encryption | Gaim-encryption | 1.14 | 1.14 |
Gaim-encryption | Gaim-encryption | 1.15 | 1.15 |