[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [Full-Disclosure] GAIM exploit
From:       Randall Perry <lists () domain-logic ! com>
Date:       2005-02-24 22:02:07
Message-ID: 6.1.2.0.0.20050224155941.03383ae0 () localhost
[Download RAW message or body]

Platform: Windows (tested only on XP and 2000, might impact others)
Application: GAIM v1.1.3
Synopsis: Cause remote crash of GAIM client.
Scenario:

By sending a file to another GAIM user, you can cause their GAIM client
to crash and completely close GAIM down.

Simply send a file to someone with parenthesis in it, and it will crash
when they accept the download (the download does not even begin, it just
crashes).

Example: filename of gaim1.1(windows).exe
will cause it to crash.

I am still playing with the debug version of GAIM, and having just run
through GTK updates to 2.4 I do not have time to digest and post those.
So far, it looks like it has to do with libglib-2.0-0.dll
I am following up with a post to GAIM developers with a complete report.

http://www.domain-logic.com/


-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.300 / Virus Database: 266.4.0 - Release Date: 2/22/2005


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic