decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gaim-encryption | Gaim-encryption | 1.13 (including) | 1.13 (including) |
Gaim-encryption | Gaim-encryption | 1.14 (including) | 1.14 (including) |
Gaim-encryption | Gaim-encryption | 1.15 (including) | 1.15 (including) |