CVE-2008-6393
psi - denial of service
EPSS 18.2%
Description
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
How to fix CVE-2008-6393
To remediate CVE-2008-6393, upgrade the affected package to a fixed version below.
- Debian/psi—upgrade to 0.12.1-1 or later
- Debian/psi—upgrade to 0.11-9 or later
Is CVE-2008-6393 being exploited?
Moderate — EPSS is 18.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.12.1-1
- from 0, < 0.11-9