The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.
Link | Tags |
---|---|
http://www.fedoranews.org/updates/FEDORA-2004-278.shtml | patch vendor advisory |
http://www.fedoranews.org/updates/FEDORA-2004-279.shtml | patch vendor advisory |
http://www.gentoo.org/security/en/glsa/glsa-200408-27.xml | vendor advisory |
http://gaim.sourceforge.net/security/?id=1 | patch vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10008 | vdb entry signature |
http://www.redhat.com/support/errata/RHSA-2004-400.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17144 | vdb entry |