Novell Home

CVE-2008-6393

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2008-6393 at MITRE

Details

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
Novell Bugzilla entry: 479815

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 10.3
  • psi >= 0.10-26.2
ZYPP Patch Nr: 6042
SAT Patch Nr: 574
openSUSE 11.0
  • psi >= 0.11.99.1-22.2
ZYPP Patch Nr: 6042
SAT Patch Nr: 574
openSUSE 11.1
  • psi-debuginfo >= 0.12-28.15.1
  • psi-debugsource >= 0.12-28.15.1
ZYPP Patch Nr: 6042
SAT Patch Nr: 574
openSUSE 11.1
  • psi >= 0.12-28.15.1
ZYPP Patch Nr: 6042
SAT Patch Nr: 574

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.