Vulnerability Details CVE-2003-0163
decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2003-0163
-
cpe:2.3:a:gaim-encryption:gaim-encryption:1.13
-
cpe:2.3:a:gaim-encryption:gaim-encryption:1.14
-
cpe:2.3:a:gaim-encryption:gaim-encryption:1.15