CVE-2005-1261

Gaim - Stack-Based Buffer Overflow via URL Parsing in Instant Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1261. PoCs published by Ron.

AI-analyzed exploit summary This is a proof-of-concept exploit for a stack overflow vulnerability in Gaim 1.2.1, triggered by processing maliciously crafted email addresses. The exploit causes a segmentation fault by overwriting the stack with a large number of 'A' characters, leading to a crash when the return address is set to 0x41414141.

Description

Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ron · cdoslinux
https://www.exploit-db.com/exploits/999

This is a proof-of-concept exploit for a stack overflow vulnerability in Gaim 1.2.1, triggered by processing maliciously crafted email addresses. The exploit causes a segmentation fault by overwriting the stack with a large number of 'A' characters, leading to a crash when the return address is set to 0x41414141.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Gaim 1.2.1
No auth needed
Prerequisites: Access to a conversation in Gaim where the exploit can be triggered via a command
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13590
Third Party Advisory, VDB Entry vendor-advisory x_refsource_fedora
http://www.securityfocus.com/archive/1/426078/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0519
Patch, Vendor Advisory x_refsource_confirm
http://gaim.sourceforge.net/security/index.php?id=16
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-429.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10725
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-432.html

Scores

EPSS 0.1240
EPSS Percentile 95.7%

Details

Status published
Products (48)
rob_flynn/gaim 0.10
rob_flynn/gaim 0.10.3
rob_flynn/gaim 0.50
rob_flynn/gaim 0.51
rob_flynn/gaim 0.52
rob_flynn/gaim 0.53
rob_flynn/gaim 0.54
rob_flynn/gaim 0.55
rob_flynn/gaim 0.56
rob_flynn/gaim 0.57
... and 38 more
Published May 11, 2005
Tracked Since Feb 18, 2026