FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

gaim -- AIM/ICQ non-UTF-8 filename crash

Affected packages
gaim < 1.4.0_1
ja-gaim < 1.4.0_1
ko-gaim < 1.4.0_1
ru-gaim < 1.4.0_1

Details

VuXML ID 09db2844-0b21-11da-bc08-0001020eed82
Discovery 2005-08-09
Entry 2005-08-12

The GAIM team reports:

A remote user could cause Gaim to crash on some systems by sending the Gaim user a file whose filename contains certain invalid characters. It is unknown what combination of systems are affected, but it is suspected that Windows users and systems with older versions of GTK+ are especially susceptible.

References

CVE Name CVE-2005-2102
URL http://gaim.sourceforge.net/security/?id=21