decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
| Software | From | Fixed in |
|---|---|---|
| gaim-encryption / gaim-encryption | 1.13 | 1.13.x |
| gaim-encryption / gaim-encryption | 1.14 | 1.14.x |
| gaim-encryption / gaim-encryption | 1.15 | 1.15.x |