CVE-2008-0672

The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:N/I:N/A:P
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
tintintintin\+\+
1.97.9
tintinwintin\+\+
1.97.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tintin++
bullseye
2.02.03-1
fixed
etch
no-dsa
sid
2.02.20-1
fixed
trixie
2.02.20-1
fixed
bookworm
2.02.20-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tintin++
karmic
Fixed 1.97.9-2
released
jaunty
Fixed 1.97.9-2
released
intrepid
Fixed 1.97.9-2
released
hardy
Fixed 1.97.9-2
released
gutsy
ignored
feisty
ignored
edgy
ignored
dapper
ignored