Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-0966
CVE-2005-0966
Description
The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- secunia.com/advisories/14815nvdPatchVendor Advisory
- sourceforge.net/project/shownotes.phpnvdPatch
- gaim.sourceforge.net/security/index.phpnvdVendor Advisory
- marc.infonvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2005_36_sudo.htmlnvd
- www.redhat.com/support/errata/RHSA-2005-365.htmlnvd
- www.securityfocus.com/archive/1/426078/100/0/threadednvd
- www.securityfocus.com/bid/13003nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19937nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19939nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9185nvd
News mentions
0No linked articles in our index yet.