Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
Centericq Centericq (not an official CPE)
Ekg Ekg 1.0 rc3 (not an official CPE)
Ekg Ekg 1.3 (not an official CPE)
Ekg Ekg 1.0 rc2 (not an official CPE)
Ekg Ekg 1.5 rc2 (not an official CPE)
Ekg Ekg 1.4 (not an official CPE)
Ekg Ekg 1.1 (not an official CPE)
Ekg Ekg 1.0 (not an official CPE)
Ekg Ekg 1.5 rc1 (not an official CPE)
Ekg Ekg 1.1 rc2 (not an official CPE)
Ekg Ekg 1.5 (not an official CPE)
Kadu Kadu (not an official CPE)
Ekg Ekg 1.1 rc1 (not an official CPE)