CVE-2008-6393
03.03.2009, 16:30
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.Enginsight
| Vendor | Product | Version |
|---|---|---|
| psi-im | psi | 𝑥 ≤ 0.12 |
| psi-im | psi | 0.1.0 |
| psi-im | psi | 0.8.6 |
| psi-im | psi | 0.8.7 |
| psi-im | psi | 0.9 |
| psi-im | psi | 0.9.1 |
| psi-im | psi | 0.9.2 |
| psi-im | psi | 0.9.3 |
| psi-im | psi | 0.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References